PT-2026-36013 · Sourcecodester · Pizzafy Ecommerce System

R3Ng4F

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-7407

CVSS v3.1

4.7

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save settings of the file /pizzafy/admin/ajax.php?action=save settings of the component Setting Handler. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7407

Affected Products

Pizzafy Ecommerce System