Description
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-04-28: | Advisory disclosed |
| 2026-04-28: | VulDB entry created |
| 2026-04-28: | VulDB entry last update |
Credits
r3du (VulDB User)
References
vuldb.com/vuln/359957 (VDB-359957 | SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting)
vuldb.com/vuln/359957/cti (VDB-359957 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/803176 (Submit #803176 | SourceCodester Pizzafy Ecommerce System 1.0 Cross Site Scripting)
github.com/joaodrmmd/VulDB-Reports/blob/main/XSS - Users.pdf
www.sourcecodester.com/