Junglewise Threat Intelligence

CVE-2026-10559: SourceCodester Pizzafy Ecommerce System local file inclusion in index.php

CVE-2026-10559 · Severity: medium · CVSS 6.3 · Published 2026-06-02

Technologies: SourceCodester Pizzafy Ecommerce System. Vendors: SourceCodester.

Executive brief

SourceCodester Pizzafy Ecommerce System 1.0 is an online shopping platform. A security flaw in the system's main entry point allows an attacker to manipulate web requests to access files they should not be able to see. This could lead to the exposure of sensitive system logs or configuration files, and in some cases, allow an attacker to take full control of the web server.

Technical details

A Local File Inclusion (LFI) vulnerability exists in SourceCodester Pizzafy Ecommerce System 1.0 within the 'page' GET parameter of index.php. The application fails to properly validate user-supplied paths and is susceptible to Null Byte Injection (%00), which can be used to bypass file extension enforcement (such as an appended .php extension). A remote attacker with low privileges can exploit this to include arbitrary files from the local file system. This can lead to sensitive information disclosure or Remote Code Execution (RCE) through techniques such as log poisoning if the attacker can inject PHP code into accessible log files. The vulnerability was demonstrated on a Windows/XAMPP environment.

Affected products

  • SourceCodester Pizzafy Ecommerce System 1.0

Timeline

  • 2026-06-02: advisory: NVD publication date
  • 2026-06-01: disclosed: Initial disclosure by VulDB

References

Related threats