CVE-2026-7225: SourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function deletemenu of the file /admin/ajax.php?action=deletemenu. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7225?
CVE-2026-7225 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive data.
How do I fix CVE-2026-7225?
To fix CVE-2026-7225, sanitize and validate the input parameters in the delete_menu function to prevent SQL injection attacks.
What systems are affected by CVE-2026-7225?
CVE-2026-7225 affects SourceCodester Pizzafy Ecommerce System version 1.0.
Can CVE-2026-7225 be exploited remotely?
Yes, CVE-2026-7225 can be exploited remotely by attackers targeting the delete_menu function via crafted requests.
What are the consequences of exploiting CVE-2026-7225?
Exploiting CVE-2026-7225 may lead to data loss, unauthorized data access, or potential corruption of the database.