CVE-2026-7393
MEDIUMSourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-7393. PoCs published by Xmyronn.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-7393, an unrestricted file upload vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, vulnerable code snippets, and screenshots demonstrating remote code execution via a PHP webshell upload.
Description
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-7393, an unrestricted file upload vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, vulnerable code snippets, and screenshots demonstrating remote code execution via a PHP webshell upload.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L