NivoCart 2.4.0 及之前版本在 forgotten.php 端点中存在可预测的密码重置令牌漏洞。该端点使用 substr(md5(mt_rand()), 0, 10) 生成恢复代码。攻击者若知道管理员的电子邮件地址,即可请求密码重置,并预测令牌以获取管理员账户访问权限。此外,该机制缺乏速率限制和令牌过期机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94104 | 8.8 HIGH | NivoCart through 2.4.0 Arbitrary File Upload RCE via filemanager |
| CVE-2026-94105 | 5.3 MEDIUM | NivoCart through 2.4.0 Destructive Configuration Write via the Password Reset Controller |
No comments yet