Impact
This vulnerability arises from an unspecified flaw in the handling of arguments in the /admin/index.php file of SourceCodester Pizzafy Ecommerce System. The flaw permits arbitrary script injection via the application’s interface, which can be exploited remotely by attackers. The impact includes the ability for attackers to execute malicious JavaScript in the context of the target’s browser, potentially leading to defacement, theft of session cookies, or other client‑side compromise.
Affected Systems
The exposed product is SourceCodester Pizzafy Ecommerce System version 1.0. No additional affected versions were identified in the CNA report. Vendors and users of this product should verify whether their installation corresponds to the reported version to determine exposure.
Risk and Exploitability
The CVSS rating of 5.3 indicates a moderate severity; however, because the vulnerability is exploitable from the internet and the exploit has been publicly disclosed, the risk to installations remains significant. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely target exposed Web servers that host the vulnerable version and can inject payloads via the admin interface, thereby compromising client‑side security.
OpenCVE Enrichment