Executive brief
RafyMrX TOKO-ONLINE-ROTI, an online bakery store application, contains a security flaw that allows users to bypass authorization checks. By manipulating specific web parameters, an attacker could perform actions they are not permitted to do, potentially compromising customer data or order integrity. This issue affects the application's ability to properly restrict access to its internal functions.
Technical details
An authorization bypass vulnerability (CWE-639/CWE-285) exists in RafyMrX TOKO-ONLINE-ROTI up to commit ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. The flaw is located in the file 'proses/add.php' and is triggered by manipulating the 'kd_cs' argument. A remote attacker with low privileges can exploit this to bypass intended access controls. The product follows a rolling release strategy, and as of the advisory date, the vendor has not responded to disclosure attempts. The vulnerability allows for unauthorized data modification or access within the application's processing logic.
Affected products
- RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
Timeline
- 2026-07-16: advisory: Initial disclosure by VulDB and NVD