CVE-2026-7227: SourceCodester Pizzafy Ecommerce System ajax.php login sql injection
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login. The manipulation of the argument e-mail results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7227?
The severity of CVE-2026-7227 is considered high due to its potential for SQL injection attacks.
How do I fix CVE-2026-7227?
To fix CVE-2026-7227, sanitize and validate user inputs in the login function to prevent SQL injection.
What component is affected by CVE-2026-7227?
CVE-2026-7227 affects the Login function in the /admin/ajax.php file of the SourceCodester Pizzafy Ecommerce System version 1.0.
What type of vulnerability is CVE-2026-7227?
CVE-2026-7227 is a SQL injection vulnerability that allows attackers to manipulate SQL queries through user input.
What impact could CVE-2026-7227 have on an organization?
CVE-2026-7227 could lead to unauthorized access to sensitive data and compromise the integrity of the ecommerce system.