PT-2026-35661 · Sourcecodester · Pizzafy Ecommerce System
Fernando Mengali
·
Published
2026-04-28
·
Updated
2026-04-29
·
CVE-2026-7224
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Pizzafy Ecommerce System version 1.0
Description
A security flaw allows remote attackers to perform SQL injection, which is a technique where malicious SQL statements are inserted into entry fields for execution. This issue occurs within the
delete cart() function located in the '/admin/ajax.php?action=delete cart' endpoint through the manipulation of the ID variable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/admin/ajax.php?action=delete cart' endpoint or disable the
delete cart() function to minimize the risk of exploitation.Exploit
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pizzafy Ecommerce System