Post
STACKFLAG
stackflag.bsky.social
did:plc:zhe53h7ajlloep2oso5pqxzj
CVE-2026-37604
The pH7Builder dating CMS (up to version 18.2.0) trusts the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers to identify a user’s IP address without checking if they come from a known proxy. Because the system…
Too many irrelevant or confusing CVEs? Use stackflag.com
#CVE #infosec
https://stackflag.com/vulnerabilities/cve-2026-37604?utm_source=bluesky&utm_medium=social&utm_campaign=cve_poster&utm_content=cve-2026-37604
2026-09-23T16:30:03.759Z