CVE-2026-10704

medium

Description

A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

References

https://www.sourcecodester.com/

https://vuldb.com/vuln/368017/cti

https://vuldb.com/vuln/368017

https://vuldb.com/submit/831321

https://vuldb.com/cve/CVE-2026-10704

https://github.com/nuiifornet/A033/blob/main/pizzafy-vulnerability.md

Details

Source: Mitre, NVD

Published: 2026-06-03

Updated: 2026-06-03

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Severity: High

CVSS v4

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00033