CVE-2026-15490: SQL Injection in TOKO-ONLINE-ROTI Product Add Endpoint
ID: 9f5d08f1-465c-5ebb-8924-03547200f797
STIX ID: report--9f5d08f1-465c-5ebb-8924-03547200f797
Feed Name: CosmicBytez Labs
A high-severity SQL injection (CVE-2026-15490, CVSS 7.3) was identified in the proses/add.php endpoint of the open-source TOKO-ONLINE-ROTI PHP application: the POST parameters kode_produk and kd_cs are directly interpolated into an INSERT SQL statement, enabling remote attackers (no privileges required) to perform database exfiltration, manipulate records, or escalate privileges; all commits up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99 are affected and recommended mitigations include prepared statements, input validation, least-privilege DB accounts, disabling error display, and deploying a WAF.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
