CVE-2026-7228
HIGHSourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-7228. PoCs published by mikecostanzi.
AI-analyzed exploit summary The repository contains no exploit code, technical analysis, or proof-of-concept for CVE-2026-7228. It only provides links to external resources for setting up virtual environments and downloading software, including a PHP e-commerce system (Pizzafy), but no details about the vulnerability itself.
Description
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Exploits (1)
The repository contains no exploit code, technical analysis, or proof-of-concept for CVE-2026-7228. It only provides links to external resources for setting up virtual environments and downloading software, including a PHP e-commerce system (Pizzafy), but no details about the vulnerability itself.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L