Predictable Password Reset Token Vulnerability in NivoCart by NivoCart
CVE-2026-94107
What is CVE-2026-94107?
NivoCart, up to version 2.4.0, has a vulnerability within its forgotten.php endpoint, where password reset tokens are generated using a predictable method. This allows attackers who have access to an administrator's email address to exploit this weakness by requesting a password reset. The generated recovery codes do not include any rate limiting or expiration mechanisms, permitting unauthorized access to administrative accounts through predictable token values. For detailed insights, refer to the product's issue tracking and more technical specifications in its reset token generation and user retrieval methods. This vulnerability poses significant security risks, and users are urged to implement necessary protective measures.
Affected Version(s)
nivocart 0 <= 2.4.0
