Impact
The vulnerability in RafyMrX TOKO-ONLINE-ROTI allows an attacker to bypass authentication controls, leading to unauthorized access to the application’s functions. It originates from a flaw that causes missing authentication, enabling remote exploitation. The weakness falls under CWE‑287 (Improper Authentication) and CWE‑306 (Missing Authentication).
Affected Systems
The affected product is RafyMrX TOKO-ONLINE-ROTI. No specific version numbers are listed because the vendor’s rolling release strategy prevents precise mapping; the vulnerability may exist in any recent or unreleased commit. Administrators must therefore consider all current builds of the application as potentially impacted until a vendor‑issued fix or version upgrade is released.
Risk and Exploitability
This vulnerability has a CVSS score of 6.9, classifying it as moderate. The EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The description states that the attack can be carried out remotely, so the likely attack vector is remote. If exploited, an attacker could gain unauthorized access to the application’s backend.
OpenCVE Enrichment