A vulnerability labeled as critical has been found in SourceCodester Pizzafy E-Commerce System 1.0 . This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order . The manipulation of the argument ID results in sql injection. This vulnerability is reported as CVE-2026-14713 . The attack can be launched remotely. Moreover, an exploit is present.