CVE-2026-7393

MEDIUM

SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-7393. PoCs published by Xmyronn.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-7393, an unrestricted file upload vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, vulnerable code snippets, and screenshots demonstrating remote code execution via a PHP webshell upload.

Description

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Exploits (1)

nomisec WRITEUP
by Xmyronn · poc
https://github.com/Xmyronn/CVE-2026-7393-RCE

This repository provides a detailed technical analysis of CVE-2026-7393, an unrestricted file upload vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, vulnerable code snippets, and screenshots demonstrating remote code execution via a PHP webshell upload.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Pizzafy Ecommerce System 1.0
Auth required
Prerequisites: Administrator access to the Pizzafy Ecommerce System
devstral-2 · analyzed Apr 29, 2026 Full analysis →

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-360118 | SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload
https://vuldb.com/vuln/360118
Signature, Permissions Required signature permissions-required
VDB-360118 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/360118/cti
Third Party Advisory third-party-advisory
Submit #803522 | SourceCodester Pizzafy Ecommerce System using PHP and MySQL 1.0 Incomplete Identification of Uploaded File Variables
https://vuldb.com/submit/803522

Scores

CVSS v3 4.7
EPSS 0.0027
EPSS Percentile 18.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (1)
SourceCodester/Pizzafy Ecommerce System 1.0
Published Apr 29, 2026
Tracked Since Apr 29, 2026