GHSA-g4x6-pg76-867rCriticalCVSS 8.1

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten...

Published
September 20, 2026
Last Modified
September 20, 2026

🔗 CVE IDs covered (1)

📋 Description

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.

🔗 References (7)