CVE-2026-7394: SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/vieworder.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7394?
CVE-2026-7394 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-7394?
To fix CVE-2026-7394, you should sanitize and validate all user inputs in the view_order.php file.
What systems are affected by CVE-2026-7394?
CVE-2026-7394 affects the SourceCodester Pizzafy Ecommerce System version 1.0.
What type of attack can CVE-2026-7394 enable?
CVE-2026-7394 can enable attackers to execute arbitrary SQL queries on the database.
Is there a patch available for CVE-2026-7394?
As of now, no official patch has been released for CVE-2026-7394.