PT-2026-35663 · Sourcecodester · Pizzafy Ecommerce System
Fernando Mengali
·
Published
2026-04-28
·
Updated
2026-04-29
·
CVE-2026-7226
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Pizzafy Ecommerce System version 1.0
Description
An issue in the
login2() function within the '/admin/ajax.php?action=login2' endpoint allows for SQL injection via the manipulation of the e-mail argument. This flaw enables remote exploitation.Recommendations
Update SourceCodester Pizzafy Ecommerce System version 1.0 to a patched version.
As a temporary workaround, restrict access to the '/admin/ajax.php?action=login2' endpoint or the
login2() function to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pizzafy Ecommerce System