LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-7394 - Vulnerability Analysis

MediumCVSS: 4.7

Last Updated: April 29, 2026

SourceCodester Pizzafy Ecommerce System - SQL Injection

Published: April 29, 2026Updated: April 29, 2026PoC AvailableRemote Exploitable

Overview

SourceCodester Pizzafy Ecommerce System 1.0 contains a sql injection caused by manipulation of the "ID" GET parameter in /admin/view_order.php, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request.

Severity & Score

Severity: Medium
CVSS Score: 4.7

Impact

Remote attackers can execute arbitrary SQL commands, potentially leading to data disclosure or modification.

Mitigation

Update to the latest version or apply vendor patches addressing this vulnerability.

Details

CVE ID
CVE-2026-7394
Severity
Medium
CVSS Score
4.7
Type
sql_injection
Status
new

CWE

  • CWE-74

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L