Impact
The flaw stems from generating password‑reset tokens with a weak, predictable routine—substr(md5(mt_rand()), 0, 10)—allowing an attacker who knows an administrator’s e‑mail to compute the token in advance. Predictability removes the randomness required to protect the reset flow, and without expiration or rate limits the attacker can reuse the same token until success. The resulting impact is administrative account takeover, which effectively grants full control of the site and all underlying systems. This vulnerability is a classic instance of CWE‑338 (Weakness in Randomness or Authentication).
Affected Systems
NivoCart, the e‑commerce platform produced by the vendor nivocart, is affected in all releases up to and including version 2.4.0. The vulnerability resides in the admin/reset (forgotten.php) endpoint used for account recovery. No newer releases beyond 2.4.0 are impacted according to the available data.
Risk and Exploitability
The CVSS score of 9.2 reflects a high‑severity danger. An EPSS score is not available, so the likelihood of exploitation cannot be quantified from EPSS data. The vulnerability is not listed in the CISA KEV catalog. Attackers can remote‑access the password-reset endpoint simply by knowing the admin’s e‑mail address; the predictability of the token and lack of throttle or expiry enable immediate exploitation. Once the token is guessed, the attacker can reset the administrator password and gain full site control.
OpenCVE Enrichment