logo

CVE-2026-15490: SQL Injection in TOKO-ONLINE-ROTI Product Add Endpoint

ID: 9f5d08f1-465c-5ebb-8924-03547200f797

STIX ID: report--9f5d08f1-465c-5ebb-8924-03547200f797

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-12

Date Updated: 2026-07-13

...
...

A high-severity SQL injection (CVE-2026-15490, CVSS 7.3) was identified in the proses/add.php endpoint of the open-source TOKO-ONLINE-ROTI PHP application: the POST parameters kode_produk and kd_cs are directly interpolated into an INSERT SQL statement, enabling remote attackers (no privileges required) to perform database exfiltration, manipulate records, or escalate privileges; all commits up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99 are affected and recommended mitigations include prepared statements, input validation, least-privilege DB accounts, disabling error display, and deploying a WAF.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.