PT-2026-95958 · Nivocart · Nivocart
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NivoCart versions prior to 2.4.1
Description
The 'forgotten.php' endpoint generates recovery codes using the
substr(md5(mt rand()), 0, 10) method, resulting in predictable password reset tokens. An attacker with knowledge of an administrator's email address can request a password reset and predict the token to gain unauthorized administrative access. This process is further facilitated by the absence of rate limiting or token expiration.Recommendations
Update NivoCart to a version newer than 2.4.0.
As a temporary mitigation, restrict access to the 'forgotten.php' endpoint.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nivocart