NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nivocart
Nivocart nivocart |
|
| Vendors & Products |
Nivocart
Nivocart nivocart |
Sun, 20 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration. | |
| Title | NivoCart through 2.4.0 Predictable Administrator Password Reset Token | |
| Weaknesses | CWE-338 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T16:48:09.091Z
Reserved: 2026-09-20T10:56:43.733Z
Link: CVE-2026-94107
No data.
Status : Received
Published: 2026-09-20T12:17:06.277
Modified: 2026-09-21T17:19:19.713
Link: CVE-2026-94107
No data.
OpenCVE Enrichment
Updated: 2026-09-21T10:02:38Z
Weaknesses