CVE-2026-7295: SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting
A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function savemenu of the file /admin/ajax.php?action=savemenu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7295?
CVE-2026-7295 is considered a high severity vulnerability due to its potential for remote exploitation through cross site scripting.
How do I fix CVE-2026-7295?
To fix CVE-2026-7295, validate and sanitize all user input in the save_menu function to prevent script injection.
What type of vulnerability is CVE-2026-7295?
CVE-2026-7295 is a cross-site scripting (XSS) vulnerability affecting the Pizzafy Ecommerce System.
Can CVE-2026-7295 be exploited remotely?
Yes, CVE-2026-7295 can be exploited remotely due to its nature of allowing script execution through manipulated inputs.
Which component of the Pizzafy Ecommerce System is affected by CVE-2026-7295?
The vulnerability CVE-2026-7295 affects the save_menu function located in the admin/ajax.php file.