Loading market data...
← Back to CVE feed

CVE-2026-93868

HIGH CVSS 8.1 View on NVD ↗

Description

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account password including administrators.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Sep 18, 2026 20:17 UTC Modified: Sep 18, 2026 21:18 UTC