CVE-2026-7266: SourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function saveorder of the file /admin/ajax.php?action=saveorder. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7266?
CVE-2026-7266 is a critical SQL injection vulnerability found in SourceCodester Pizzafy Ecommerce System 1.0.
How do I fix CVE-2026-7266?
To fix CVE-2026-7266, validate and sanitize all user inputs related to the save_order function in ajax.php.
What types of attacks can CVE-2026-7266 be exploited for?
CVE-2026-7266 can be exploited for SQL injection attacks, allowing attackers to manipulate the database.
Who is affected by CVE-2026-7266?
CVE-2026-7266 affects users of SourceCodester Pizzafy Ecommerce System version 1.0.
What component is vulnerable in CVE-2026-7266?
The vulnerable component in CVE-2026-7266 is the save_order function in the admin/ajax.php file.