Vulnerability Description
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/joaodrmmd/VulDB-Reports/blob/main/XSS%20-%20Orders.pdf
- https://vuldb.com/submit/803175
- https://vuldb.com/vuln/359956
- https://vuldb.com/vuln/359956/cti
- https://www.sourcecodester.com/
FAQ
What is CVE-2026-7296?
CVE-2026-7296 is a vulnerability with a CVSS score of 2.4 (LOW). A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument ...
How severe is CVE-2026-7296?
CVE-2026-7296 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-7296?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.