Description
A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Problem types
Product status
Timeline
| 2026-04-28: | Advisory disclosed |
| 2026-04-28: | VulDB entry created |
| 2026-04-28: | VulDB entry last update |
Credits
r3du (VulDB User)
References
vuldb.com/vuln/359955 (VDB-359955 | SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting)
vuldb.com/vuln/359955/cti (VDB-359955 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/803173 (Submit #803173 | SourceCodester Pizzafy Ecommerce System 1.0 Cross Site Scripting)
github.com/joaodrmmd/VulDB-Reports/blob/main/XSS – Menu.pdf
www.sourcecodester.com/
