PT-2026-35710 · Sourcecodester · Pizzafy Ecommerce System

Fernando Mengali

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7266

CVSS v3.1

6.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save order of the file /admin/ajax.php?action=save order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7266

Affected Products

Pizzafy Ecommerce System