CVE-2026-68954: Toptech TMS7 and TopHAT SQL Injection
The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Toptech TMS7to a version that resolves this vulnerability.Fixed in 7.8
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, has low attack complexity, requires high privileges, and does not require user interaction.
What is the potential impact of successful exploitation?
The reported impact includes high confidentiality loss, low integrity impact, and high availability impact. The CVSS vector also indicates that the impact can extend beyond the vulnerable component’s security scope.
Which systems should be reviewed?
Organizations should assess deployments of Toptech TMS7 and Toptech TopHAT, particularly where authenticated users with high privileges can reach the application over the network.