CVE-2026-7293: SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function deletecategory of the file /admin/ajax.php?action=deletecategory. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7293?
CVE-2026-7293 is classified as a critical SQL injection vulnerability affecting SourceCodester Pizzafy Ecommerce System 1.0.
How do I fix CVE-2026-7293?
To fix CVE-2026-7293, sanitize and validate all user inputs in the delete_category function to prevent SQL injection.
What are the potential impacts of exploiting CVE-2026-7293?
Exploiting CVE-2026-7293 can allow an attacker to perform unauthorized database operations, potentially compromising sensitive data.
Is CVE-2026-7293 remote exploitable?
Yes, CVE-2026-7293 can be exploited remotely, making it particularly dangerous if not mitigated.
Which version of SourceCodester Pizzafy Ecommerce System is affected by CVE-2026-7293?
CVE-2026-7293 specifically affects version 1.0 of the SourceCodester Pizzafy Ecommerce System.