Impact
The flaw in RafyMrX TOKO-ONLINE-ROTI allows an attacker to inject arbitrary SQL by manipulating the kode_produk and kd_cs parameters in add.php. The injection can be triggered through a crafted remote request, potentially compromising the confidentiality and integrity of the database. The weakness is recognized as a combination of CWE-74 and CWE-89 vulnerabilities, and a public exploit has been released.
Affected Systems
All releases of the Toko‑Online‑Roti application, including those up to the commit ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99, are affected. Because the product follows a rolling‑release model, explicit version numbers are not provided and any current production deployment may be vulnerable until a fix is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating medium severity, and an EPSS score of less than 1 %. It is not listed in the CISA KEV catalogue. The attack vector is remote; a malicious actor can trigger the injection by sending a crafted request to add.php. The low EPSS score suggests a low likelihood of exploitation, but the risk is contingent on the application's exposure to the internet.
OpenCVE Enrichment