CVE-2026-71189: Toptech TMS7 and TopHAT Cross-site Scripting
An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Toptech TMS7 and TopHATto a version that resolves this vulnerability.Fixed in 7.8
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs network access and low-level privileges in the application. Exploitation also requires another application user to interact with the attacker-crafted request.
What is the expected security impact?
The supplied JavaScript executes in the victim's browser under that user's application session. The reported CVSS vector indicates low confidentiality impact, with no integrity or availability impact.