PT-2026-35663 · Sourcecodester · Pizzafy Ecommerce System

Fernando Mengali

·

Published

2026-04-28

·

Updated

2026-04-29

·

CVE-2026-7226

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Pizzafy Ecommerce System version 1.0
Description An issue in the login2() function within the '/admin/ajax.php?action=login2' endpoint allows for SQL injection via the manipulation of the e-mail argument. This flaw enables remote exploitation.
Recommendations Update SourceCodester Pizzafy Ecommerce System version 1.0 to a patched version. As a temporary workaround, restrict access to the '/admin/ajax.php?action=login2' endpoint or the login2() function to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7226

Affected Products

Pizzafy Ecommerce System