NivoCart 2.4.0 及更早版本存在一个破坏性配置写入漏洞,位于管理员密码重置控制器中。该漏洞允许未经身份验证的攻击者通过提供无效的 code 参数来禁用密码恢复功能。攻击者可发送一个缺失或 code 参数不正确的 GET 请求,从而将 config_password 配置项重写为 0,导致自助密码恢复功能被禁用,直至管理员手动重新启用该功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94104 | 8.8 HIGH | NivoCart through 2.4.0 Arbitrary File Upload RCE via filemanager |
| CVE-2026-94107 | 8.1 HIGH | NivoCart through 2.4.0 Predictable Administrator Password Reset Token |
No comments yet