Impact
The vulnerability lies in the screenID query string used by the electronic transaction queue viewer in the manual transactions section. An attacker can supply malicious SQL payloads that trigger time‑based delays, revealing the existence or non‑existence of data. This blind injection allows remote extraction of database information, compromising confidentiality but not directly enabling code execution.
Affected Systems
Both Toptech Systems TMS7 and TopHAT are susceptible. The vulnerability affects releases prior to version 7.8, which contains the fix. Specific affected version ranges are not listed, so any pre‑7.8 installation is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. While an EPSS score is not available, the lack of a CISA KEV listing suggests no publicly known exploitation yet, but the attack vector is remote via the web interface – it is inferred that an attacker could supply a crafted screenID. The combination of high severity and potential ease of exploitation makes the risk significant and warrants timely mitigation.
OpenCVE Enrichment