CVE-2026-7294: SourceCodester Pizzafy Ecommerce System index.php save_settings cross site scripting
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function savesettings of the file /admin/index.php?page=savesettings. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7294?
CVE-2026-7294 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-7294?
To fix CVE-2026-7294, sanitize and validate all input fields in the save_settings function to prevent XSS attacks.
What software is affected by CVE-2026-7294?
CVE-2026-7294 affects SourceCodester Pizzafy Ecommerce System version 1.0.
Can CVE-2026-7294 be exploited remotely?
Yes, CVE-2026-7294 can be exploited remotely, allowing attackers to initiate cross-site scripting attacks.
What type of vulnerability is CVE-2026-7294?
CVE-2026-7294 is a cross-site scripting (XSS) vulnerability found in the save_settings function.