Junglewise Threat Intelligence

CVE-2026-16226: SourceCodester Pizzafy Ecommerce System unrestricted upload in save_settings

CVE-2026-16226 · Severity: medium · CVSS 4.7 · Published 2026-07-19

Technologies: SourceCodester Pizzafy Ecommerce System. Vendors: SourceCodester.

Executive brief

SourceCodester Pizzafy Ecommerce System, a web application for managing online pizza sales, contains a security flaw in its administrative settings. An attacker with administrative access can upload malicious files to the server, potentially leading to a complete takeover of the website or disruption of business operations. This could result in the theft of customer data or the defacement of the online store.

Technical details

An unrestricted file upload vulnerability exists in SourceCodester Pizzafy Ecommerce System 1.0 within the save_settings function of /admin/admin_class_novo.php. The vulnerability is triggered by manipulating the 'img' argument, which fails to properly validate file types or extensions before saving them to the server. A remote attacker with high-level privileges (administrator) can exploit this to upload and execute arbitrary code, such as a PHP web shell. This can lead to full system compromise, unauthorized data access, or service disruption. No official patch has been identified at this time.

Affected products

  • SourceCodester Pizzafy Ecommerce System 1.0

Timeline

  • 2026-07-19: disclosed: Initial vulnerability publication

References

Related threats