CVE-2026-7394 - Vulnerability Analysis
MediumCVSS: 4.7Last Updated: April 29, 2026
SourceCodester Pizzafy Ecommerce System - SQL Injection
Published: April 29, 2026Updated: April 29, 2026PoC AvailableRemote Exploitable
Overview
SourceCodester Pizzafy Ecommerce System 1.0 contains a sql injection caused by manipulation of the "ID" GET parameter in /admin/view_order.php, letting remote attackers execute arbitrary SQL commands, exploit requires crafted request.
Severity & Score
Severity: Medium
CVSS Score: 4.7
Impact
Remote attackers can execute arbitrary SQL commands, potentially leading to data disclosure or modification.
Mitigation
Update to the latest version or apply vendor patches addressing this vulnerability.
References
Related Resources
Details
- CVE ID
- CVE-2026-7394
- Severity
- Medium
- CVSS Score
- 4.7
- Type
- sql_injection
- Status
- new
CWE
- CWE-74
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L