Junglewise Threat Intelligence

CVE-2026-15489: RafyMrX TOKO-ONLINE-ROTI SQL injection in login.php

CVE-2026-15489 · Severity: high · CVSS 7.3 · Published 2026-07-12

Technologies: RafyMrX TOKO-ONLINE-ROTI. Vendors: RafyMrX.

Executive brief

RafyMrX TOKO-ONLINE-ROTI, an e-commerce application, contains a security flaw in its login system. An attacker can exploit this to bypass security controls or access sensitive database information without needing a valid account. This could lead to unauthorized access to the store's management interface or customer data.

Technical details

A SQL injection vulnerability exists in the 'proses/login.php' file of RafyMrX TOKO-ONLINE-ROTI. The application fails to properly sanitize the 'Username' argument before using it in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the login endpoint. Successful exploitation could allow for authentication bypass or arbitrary data extraction from the underlying database. As of the advisory date, no patch has been confirmed by the vendor.

Affected products

  • RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99

Timeline

  • 2026-07-12: advisory: Initial disclosure by VulDB and NVD

References

Related threats