logo

CVE-2026-15489: SQL Injection in TOKO-ONLINE-ROTI Login Endpoint

ID: 71388139-7cbf-593a-8455-58faa583bdeb

STIX ID: report--71388139-7cbf-593a-8455-58faa583bdeb

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-12

Date Updated: 2026-07-13

...
...

## Executive Summary A high-severity SQL injection (CVE-2026-15489, CVSS 7.3) has been identified in the TOKO-ONLINE-ROTI bakery management application: the proses/login.php endpoint uses unsanitized Username input allowing unauthenticated remote attackers to bypass authentication, exfiltrate or manipulate database contents; the report includes PoC payloads, impact analysis, detection indicators, and recommended mitigations (prepared statements, input validation, least-privilege DB user, WAF, and password hashing).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.