← Back to CVE search

CVE-2026-7294

SourceCodester Pizzafy Ecommerce System

Description

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_settings. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS 2.4EPSS 0.20600000000000002%Risk 0.24
View source
Published
2026-04-28 19:37:48
Affected versions
==1.0
Type
Package
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N