CVE-2026-7393 PUBLISHED

SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload

Assigner: VulDB
Reserved: 29.04.2026 Published: 29.04.2026 Updated: 29.04.2026

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.1

Product Status

Vendor SourceCodester
Product Pizzafy Ecommerce System
Versions
  • Version 1.0 is affected

Credits

  • imad alvi (VulDB User) reporter

References

Problem Types

  • Unrestricted Upload CWE
  • Improper Access Controls CWE