CVE-2026-7266
Published
CVSS v3
6.3
MEDIUM
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT
Description
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.php?action=save_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Repository containing security vulnerability reports submitted to VulnDB. A structured repository of vulnerability reports submitted to VulnDB, including detailed technical analysis, proof-of-concept (PoC), and reproducible steps to validate each issue