Rafymrx · Toko-Online-Roti · CVE-2026-15489
**Name of the Vulnerable Software and Affected Versions**
RafyMrX TOKO-ONLINE-ROTI versions up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
**Description**
An issue exists in the `proses/login.php` file where manipulation of the `Username` argument allows for SQL injection, a technique used to interfere with the queries that an application makes to its database. This flaw enables remote exploitation.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.