PT-2026-35665 · Sourcecodester · Pizzafy Ecommerce System

Fernando Mengali

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7228

CVSS v3.1

7.3

High

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get cart count of the file /admin/ajax.php?action=get cart count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7228

Affected Products

Pizzafy Ecommerce System