Executive brief
RafyMrX TOKO-ONLINE-ROTI, an e-commerce application, contains a security flaw in its login system. An attacker can exploit this to bypass security controls or access sensitive database information without needing a valid account. This could lead to unauthorized access to the store's management interface or customer data.
Technical details
A SQL injection vulnerability exists in the 'proses/login.php' file of RafyMrX TOKO-ONLINE-ROTI. The application fails to properly sanitize the 'Username' argument before using it in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP requests to the login endpoint. Successful exploitation could allow for authentication bypass or arbitrary data extraction from the underlying database. As of the advisory date, no patch has been confirmed by the vendor.
Affected products
- RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
Timeline
- 2026-07-12: advisory: Initial disclosure by VulDB and NVD