Impact
A flaw exists in the login functionality of RafyMrX TOKO-ONLINE-ROTI where tampering with the Username field permits a remote attacker to inject arbitrary SQL code. The consequence is unauthorized access to the database, potentially exposing sensitive information or allowing further compromise. The issue is classified by CWE-74 and CWE-89 for SQL injection weaknesses.
Affected Systems
The affected product is RafyMrX's TOKO-ONLINE-ROTI, specifically any deployment tied to or newer than the commit identifier ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. No explicit release numbers are provided, as the vendor uses a rolling release schedule, so any instance running that codebase is likely vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. Its EPSS score is below 1%, suggesting that spontaneous exploitation attempts are uncommon, but the exploit code is publicly available and remote exploitation is straightforward via the login endpoint. The vulnerability is not listed in CISA KEV, so there is no known widespread active exploitation as of the last update.
OpenCVE Enrichment