


Perceptive Security
SOC/SIEM Consultancy

A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=del…
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 07:02:19
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability (CVE-2026-7224) has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. The flaw affects the delete_cart function in /admin/ajax.php?action=delete_cart where manipulation of the ID argument leads to SQL injection. The vulnerability can be exploited remotely and a public exploit has been released, making it actively exploitable. This affects the admin panel functionality of the e-commerce system, potentially allowing attackers to access or manipulate the underlying database.
Technical details
Mitigation steps:
Affected products:
SourceCodester Pizzafy Ecommerce System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-7224
https://github.com/fernando-mengali/vulndb-submissions/blob/main/01-vul-SQLI.md
https://vuldb.com/submit/802387
https://vuldb.com/vuln/359824
https://vuldb.com/vuln/359824/cti
https://www.sourcecodester.com/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
