PT-2026-35813 · Sourcecodester · Pizzafy Ecommerce System

Fernando Mengali

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7293

CVSS v2.0

5.8

Medium

AV:N/AC:L/Au:M/C:P/I:P/A:P
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete category of the file /admin/ajax.php?action=delete category. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7293

Affected Products

Pizzafy Ecommerce System