Executive brief
A security vulnerability has been identified in TOKO-ONLINE-ROTI, an online bakery store application. The software fails to properly verify user identity for certain functions, which could allow an unauthorized person to access or modify parts of the system remotely. This could lead to unauthorized changes to the store's data or disruption of its online operations.
Technical details
A vulnerability classified as missing authentication (CWE-306/CWE-287) exists in RafyMrX TOKO-ONLINE-ROTI up to commit ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. The flaw allows a remote attacker to perform actions without providing valid credentials. The specific affected component is not identified in the advisory, but the attack vector is network-based and requires no user interaction or prior privileges. As the product follows a rolling release strategy, specific version numbers are not available. The vendor has not responded to the disclosure.
Affected products
- RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
Timeline
- 2026-07-12: advisory: Initial disclosure by VulDB and NVD