Description
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unknown processing of the file /admin/index.php. Such manipulation of the argument page leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-05-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from an unspecified flaw in the handling of arguments in the /admin/index.php file of SourceCodester Pizzafy Ecommerce System. The flaw permits arbitrary script injection via the application’s interface, which can be exploited remotely by attackers. The impact includes the ability for attackers to execute malicious JavaScript in the context of the target’s browser, potentially leading to defacement, theft of session cookies, or other client‑side compromise.

Affected Systems

The exposed product is SourceCodester Pizzafy Ecommerce System version 1.0. No additional affected versions were identified in the CNA report. Vendors and users of this product should verify whether their installation corresponds to the reported version to determine exposure.

Risk and Exploitability

The CVSS rating of 5.3 indicates a moderate severity; however, because the vulnerability is exploitable from the internet and the exploit has been publicly disclosed, the risk to installations remains significant. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely target exposed Web servers that host the vulnerable version and can inject payloads via the admin interface, thereby compromising client‑side security.

Generated by OpenCVE AI on May 8, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a version that resolves the XSS flaw in /admin/index.php
  • Implement server‑side input validation and output encoding for all parameters processed by the admin interface to mitigate the possibility of script injection
  • Restrict access to /admin/index.php by enforcing strong authentication and ensuring that only authorized personnel can reach the page
  • Deploy a web application firewall or equivalent filtering to detect and block malicious XSS payloads before they reach sensitive pages

Generated by OpenCVE AI on May 8, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 08 May 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester pizzafy Ecommerce System
Vendors & Products Sourcecodester
Sourcecodester pizzafy Ecommerce System

Fri, 08 May 2026 00:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unknown processing of the file /admin/index.php. Such manipulation of the argument page leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Title SourceCodester Pizzafy Ecommerce System index.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Pizzafy Ecommerce System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-07T23:45:10.695Z

Reserved: 2026-05-07T16:42:35.185Z

Link: CVE-2026-8117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-08T00:16:10.320

Modified: 2026-05-08T00:16:10.320

Link: CVE-2026-8117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-08T02:30:42Z

Weaknesses