Executive brief
A security vulnerability exists in TOKO-ONLINE-ROTI, an online bakery shop application. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of customer information or disruption of the store's operations. Because a public exploit is available and the vendor has not responded to reports, the risk to active installations is high.
Technical details
A SQL injection vulnerability exists in the RafyMrX TOKO-ONLINE-ROTI web application through the 'proses/add.php' endpoint. The vulnerability is caused by improper neutralization of special elements in the 'kode_produk' and 'kd_cs' parameters. A remote, unauthenticated attacker can exploit this by sending crafted HTTP requests to manipulate database queries. This can lead to unauthorized data retrieval, modification, or deletion. A public exploit has been released, and the vendor has not provided a patch as of the disclosure date.
Affected products
- RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
Timeline
- 2026-07-12: disclosed: Vulnerability disclosed via VulDB and NVD
- 2026-07-12: advisory