CVE-2026-15489: SQL Injection in TOKO-ONLINE-ROTI Login Endpoint
ID: 71388139-7cbf-593a-8455-58faa583bdeb
STIX ID: report--71388139-7cbf-593a-8455-58faa583bdeb
Feed Name: CosmicBytez Labs
## Executive Summary A high-severity SQL injection (CVE-2026-15489, CVSS 7.3) has been identified in the TOKO-ONLINE-ROTI bakery management application: the proses/login.php endpoint uses unsanitized Username input allowing unauthenticated remote attackers to bypass authentication, exfiltrate or manipulate database contents; the report includes PoC payloads, impact analysis, detection indicators, and recommended mitigations (prepared statements, input validation, least-privilege DB user, WAF, and password hashing).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
