CVE-2026-7265: SourceCodester Pizzafy Ecommerce System index.php category sql injection
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7265?
CVE-2026-7265 has been classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-7265?
To fix CVE-2026-7265, ensure proper input validation and use prepared statements to prevent SQL injection.
Which software versions are affected by CVE-2026-7265?
CVE-2026-7265 affects SourceCodester Pizzafy Ecommerce System version 1.0.
What type of attack does CVE-2026-7265 allow?
CVE-2026-7265 allows attackers to execute arbitrary SQL queries against the database through the vulnerable category parameter.
What is the impact of CVE-2026-7265 on the web application?
CVE-2026-7265 can lead to unauthorized data access and manipulation in the web application.