CVE-2026-7394
MEDIUMSourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-7394. PoCs published by Xmyronn.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-7394, an SQL injection vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, screenshots, and sqlmap usage to demonstrate the exploitation of the 'id' parameter in the admin/view_order.php endpoint.
Description
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-7394, an SQL injection vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, screenshots, and sqlmap usage to demonstrate the exploitation of the 'id' parameter in the admin/view_order.php endpoint.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L