PT-2026-36014 · Sourcecodester · Pizzafy Ecommerce System

R3Ng4F

·

Published

2026-04-29

·

Updated

2026-04-29

·

CVE-2026-7408

CVSS v3.1

4.7

Medium

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save menu of the file /admin/ajax.php?action=save menu. Performing a manipulation results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

Exploit

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7408

Affected Products

Pizzafy Ecommerce System