Description
NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.
Published: 2026-09-20
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Administrative Account Takeover
Action: Immediate Upgrade
AI Analysis

Impact

The flaw stems from generating password‑reset tokens with a weak, predictable routine—substr(md5(mt_rand()), 0, 10)—allowing an attacker who knows an administrator’s e‑mail to compute the token in advance. Predictability removes the randomness required to protect the reset flow, and without expiration or rate limits the attacker can reuse the same token until success. The resulting impact is administrative account takeover, which effectively grants full control of the site and all underlying systems. This vulnerability is a classic instance of CWE‑338 (Weakness in Randomness or Authentication).

Affected Systems

NivoCart, the e‑commerce platform produced by the vendor nivocart, is affected in all releases up to and including version 2.4.0. The vulnerability resides in the admin/reset (forgotten.php) endpoint used for account recovery. No newer releases beyond 2.4.0 are impacted according to the available data.

Risk and Exploitability

The CVSS score of 9.2 reflects a high‑severity danger. An EPSS score is not available, so the likelihood of exploitation cannot be quantified from EPSS data. The vulnerability is not listed in the CISA KEV catalog. Attackers can remote‑access the password-reset endpoint simply by knowing the admin’s e‑mail address; the predictability of the token and lack of throttle or expiry enable immediate exploitation. Once the token is guessed, the attacker can reset the administrator password and gain full site control.

Generated by OpenCVE AI on September 20, 2026 at 13:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest NivoCart release to remove the vulnerable token generator and any other associated security issues.
  • If upgrading cannot be performed immediately, block or restrict password‑reset functionality for administrator accounts or require additional authentication (e.g., a one‑time code or two‑factor).
  • Replace the existing token logic with a cryptographically secure random token generator, enforce short expiration times, and apply rate limiting to reset requests.
  • Continuously monitor reset requests and token usage for abnormal patterns indicating abuse.

Generated by OpenCVE AI on September 20, 2026 at 13:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nivocart
Nivocart nivocart
Vendors & Products Nivocart
Nivocart nivocart

Sun, 20 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.
Title NivoCart through 2.4.0 Predictable Administrator Password Reset Token
Weaknesses CWE-338
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Nivocart Nivocart
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T16:48:09.091Z

Reserved: 2026-09-20T10:56:43.733Z

Link: CVE-2026-94107

cve-icon Vulnrichment

Updated: 2026-09-21T16:48:04.045Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T12:17:06.277

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-94107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:38Z

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)