Impact
The vulnerability is a CAPTCHA bypass that permits an unauthenticated attacker to force form submission by supplying a client‑chosen form ID to PFBC Form::isValid(). This flaw allows the attacker to load a form that normally requires solving a CAPTCHA, such as login or search, and then submit that form ID together with data for other forms like contact, comment, forum, invite or signup. By doing so, the attacker can automate abuse, spamming, or excessive posting, effectively bypassing the intended input validation. The weakness is classified as CWE‑807, indicating an improper neutralization of conditions that allows the attacker to override expected control flow.
Affected Systems
Affected systems are installations of the pH7Builder Social Dating CMS supplied by ph7software. The issue exists in all releases prior to v19.3.0, including the 19.2.0 branch. Forms that rely on the PFBC library for validation—such as contact, comment, forum, invite, signup as well as forms that load a CAPTCHA‑free alternate form—are vulnerable when an attacker can supply an arbitrary form ID.
Risk and Exploitability
The CVSS score of 6.9 suggests a moderate impact. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation. However, the attack vector is likely remote via HTTP/HTTPS; any non‑authenticated user can craft a request containing a form ID, and because the application does not enforce that the ID matches the intended form, an attacker can bypass the CAPTCHA. The risk is primarily operational, enabling automated spam or abuse. Prompt application of the vendor’s patch is the recommended course of action.
OpenCVE Enrichment