Description
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Problem types
Product status
Timeline
| 2026-04-29: | Advisory disclosed |
| 2026-04-29: | VulDB entry created |
| 2026-04-29: | VulDB entry last update |
Credits
imad alvi (VulDB User)
References
vuldb.com/vuln/360118 (VDB-360118 | SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload)
vuldb.com/vuln/360118/cti (VDB-360118 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/803522 (Submit #803522 | SourceCodester Pizzafy Ecommerce System using PHP and MySQL 1.0 Incomplete Identification of Uploaded File Variables)
github.com/…Code-Execution-in-Pizzafy-Ecommerce-System.git
www.sourcecodester.com/
