VYPR
Low severity2.4NVD Advisory· Published Apr 28, 2026· Updated Apr 29, 2026

CVE-2026-7294

CVE-2026-7294

Description

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_settings. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2026-7294 is a reflected XSS in SourceCodester Pizzafy Pizzafy Ecommerce System 1.0 via the Name parameter in save_settings.

The vulnerability exists in SourceCodester Pizzafy Ecommerce System 1.0. The flaw is located in the save_settings function within /admin/index.php?page=save_settings. The manipulation of the Name argument allows for cross-site scripting (XSS) [1]. This is a reflected XSS vulnerability that can be triggered remotely.

An attacker can send a crafted request to the vulnerable endpoint with malicious JavaScript in the Name parameter. No authentication is required to exploit the vulnerability have been published and no authentication is required to trigger it, as the save_settings functionality is accessible without prior login [1].

Successful exploitation could allow an attacker to execute arbitrary HTML and JavaScript in the context of the victim's browser. This could lead to session hijacking, defacement, or theft of sensitive information within the application's domain of the application [1]. The impact is limited by the low privileges of the attacked component.

The vendor, SourceCodester, has been notified but the software's EOL status is unclear. [2]. A proof-of-concept exploit has been published, making the vulnerability more accessible to attackers [1]. No official advisory from the project maintainer has been identified, users should consider input validation or upgrading if a fix becomes available.

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.