Description
The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.
Published: 2026-09-29
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to potential unauthorized data access or modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a time-based blind SQL injection in the "search" parameter used by the view audit logs feature within the utilities section. An attacker can inject SQL code that the backend database executes, allowing the attacker to read or alter sensitive data stored in the database. This weakness is identified as CWE-89, which directly relates to untrusted input being inserted into SQL statements.

Affected Systems

The issue affects all installations of Toptech Systems products TMS7 and TopHAT that use a version older than 7.8. The publicly released fix is available in release 7.8, so any deploying an earlier version remains vulnerable.

Risk and Exploitability

With a CVSS score of 8.5, the vulnerability is classified as high severity. While EPSS data is not available, the lack of defensive controls around the "search" parameter suggests that exploitation is feasible over the web interface, making the attack vector likely remote. Based on the description, it is inferred that the attack vector is remote via the web interface. The vulnerability is not listed in the CISA KEV catalog, but the potential for data compromise warrants immediate attention.

Generated by OpenCVE AI on September 30, 2026 at 10:49 UTC.

Remediation

Vendor Solution

Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security


OpenCVE Recommended Actions

  • Upgrade all TMS7 and TopHAT deployments to release 7.8 or newer to obtain the fixed code.
  • If upgrading is not immediately possible, temporarily disable the audit logs utility in the utilities section to eliminate the vulnerable input path.
  • Restrict HTTP access to the utilities endpoints to trusted network segments and enforce strict authentication and authorization controls.

Generated by OpenCVE AI on September 30, 2026 at 10:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.
Title Toptech TMS7 and TopHAT SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-30T15:28:15.150Z

Reserved: 2026-08-10T17:31:09.976Z

Link: CVE-2026-63713

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T22:17:11.487

Modified: 2026-09-30T16:46:43.953

Link: CVE-2026-63713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T11:00:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')