Destructive Configuration Write Vulnerability in NivoCart Admin Password Reset Controller
CVE-2026-94105
6.9MEDIUM
What is CVE-2026-94105?
NivoCart versions up to 2.4.0 are affected by a vulnerability in the admin password reset controller that can be exploited by unauthenticated attackers. This flaw allows attackers to disable the password recovery functionality by sending a GET request with a missing or incorrect code parameter. As a result, the system rewrites the configuration setting for password recovery to zero, preventing users from recovering their accounts without administrator intervention. This vulnerability poses a significant risk to user data and account security.
Affected Version(s)
nivocart 0 <= 2.4.0
