Impact
The vulnerability in pH7 Builder allows an attacker who has obtained a user’s password to circumvent the second authentication factor by submitting an unlimited number of 6‑digit one‑time passwords to the VerificationCodeFormProcess.php endpoint, leading directly to account takeover. This flaw is a manifestation of CWE‑307.
Affected Systems
The flaw affects all installations of pH7 Social Dating CMS (pH7Builder) from ph7software running any version earlier than 18.5.0. No sub‑module or more granular version data is documented.
Risk and Exploitability
The CVSS score of 7.6 classifies this issue as high severity. The EPSS score is not available, so the precise exploitation likelihood is unknown, yet the vulnerability can be exploited remotely via the web interface. It is not listed in the CISA KEV catalog. Because attackers who know the account password can brute‑force the 6‑digit TOTP without limit, the risk to privileged accounts is significant. The lack of a lockout or rate‑limit mechanism makes successful exploitation straightforward.
OpenCVE Enrichment