Rafymrx · Toko-Online-Roti · CVE-2026-15490
**Name of the Vulnerable Software and Affected Versions**
RafyMrX TOKO-ONLINE-ROTI versions up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
**Description**
A remote SQL injection flaw exists in the `proses/add.php` file. This issue occurs when the `kode produk` or `kd cs` arguments are manipulated, allowing an attacker to execute arbitrary SQL commands on the database.
**Recommendations**
As a temporary workaround, restrict access to the `proses/add.php` file or avoid using the `kode produk` and `kd cs` parameters until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.