Impact
The vulnerability is a time-based blind SQL injection in the "search" parameter used by the view audit logs feature within the utilities section. An attacker can inject SQL code that the backend database executes, allowing the attacker to read or alter sensitive data stored in the database. This weakness is identified as CWE-89, which directly relates to untrusted input being inserted into SQL statements.
Affected Systems
The issue affects all installations of Toptech Systems products TMS7 and TopHAT that use a version older than 7.8. The publicly released fix is available in release 7.8, so any deploying an earlier version remains vulnerable.
Risk and Exploitability
With a CVSS score of 8.5, the vulnerability is classified as high severity. While EPSS data is not available, the lack of defensive controls around the "search" parameter suggests that exploitation is feasible over the web interface, making the attack vector likely remote. Based on the description, it is inferred that the attack vector is remote via the web interface. The vulnerability is not listed in the CISA KEV catalog, but the potential for data compromise warrants immediate attention.
OpenCVE Enrichment