{"id":"CVE-2026-93868","published":"2026-09-18T20:17:34.633","lastModified":"2026-09-22T20:53:07.383","description":"Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account password including administrators.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-338"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Cotonti/Cotonti","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/blob/1.0.0/modules/users/inc/users.passrecover.php","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/issues/1890","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/pull/1898","tags":[]},{"url":"https://www.vulncheck.com/advisories/cotonti-through-1.0.0-predictable-password-recovery-token-via-weak-prng","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/issues/1890","tags":[]}],"exploitRefs":[{"url":"https://github.com/Cotonti/Cotonti","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/blob/1.0.0/modules/users/inc/users.passrecover.php","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/issues/1890","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/pull/1898","tags":[]},{"url":"https://github.com/Cotonti/Cotonti/issues/1890","tags":[]}],"hasPoc":true,"ai":null}