CVE-2026-7297
SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
SourceCodester · Pizzafy Ecommerce Systempublic PoCs found — 1
cve_referencegithub.com/joaodrmmd/VulDB-Reports/blob/main/XSS%20-%20Users.pdfunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →