medium · CVSS v3 5.3 · CVSS v4 6.9
CVE-2026-94105
NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller t…
Description
NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter. Attackers can send a GET request with a missing or incorrect code to rewrite the config_password setting to 0, disabling self-service password recovery until an administrator manually re-enables it.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- 6.9
- EPSS
- —