CVE-2026-7394

MEDIUM

SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-7394. PoCs published by Xmyronn.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-7394, an SQL injection vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, screenshots, and sqlmap usage to demonstrate the exploitation of the 'id' parameter in the admin/view_order.php endpoint.

Description

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

Exploits (1)

nomisec WRITEUP
by Xmyronn · poc
https://github.com/Xmyronn/CVE-2026-7394-SQLI

This repository provides a detailed technical analysis of CVE-2026-7394, an SQL injection vulnerability in Pizzafy Ecommerce System 1.0. It includes a step-by-step proof of concept, screenshots, and sqlmap usage to demonstrate the exploitation of the 'id' parameter in the admin/view_order.php endpoint.

Classification
Writeup 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Pizzafy Ecommerce System 1.0
Auth required
Prerequisites: Authenticated administrator access · Burp Suite or similar intercepting proxy · sqlmap for automated exploitation
devstral-2 · analyzed Apr 29, 2026 Full analysis →

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-360119 | SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection
https://vuldb.com/vuln/360119
Signature, Permissions Required signature permissions-required
VDB-360119 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/360119/cti
Third Party Advisory third-party-advisory
Submit #803523 | SourceCodester Pizzafy Ecommerce System using PHP and MySQL 1.0 SQL Injection
https://vuldb.com/submit/803523

Scores

CVSS v3 4.7
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
SourceCodester/Pizzafy Ecommerce System 1.0
Published Apr 29, 2026
Tracked Since Apr 29, 2026