Impact
The flaw is an unrestricted file upload in the save_settings function of admin_class_novo.php, allowing an attacker to supply any file via the img argument. Depending on the file type and server configuration, this could lead to remote code execution or the placement of malicious files on the server.
Affected Systems
SourceCodester Pizzafy Ecommerce System 1.0, specifically the admin_class_novo.php module.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk level. An EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, through the web interface, with no need for local privileges.
OpenCVE Enrichment