Description
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
Published: 2026-09-29
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection via the screenID parameter enabling time‑based blind data exfiltration
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the screenID query string used by the electronic transaction queue viewer in the manual transactions section. An attacker can supply malicious SQL payloads that trigger time‑based delays, revealing the existence or non‑existence of data. This blind injection allows remote extraction of database information, compromising confidentiality but not directly enabling code execution.

Affected Systems

Both Toptech Systems TMS7 and TopHAT are susceptible. The vulnerability affects releases prior to version 7.8, which contains the fix. Specific affected version ranges are not listed, so any pre‑7.8 installation is at risk.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity. While an EPSS score is not available, the lack of a CISA KEV listing suggests no publicly known exploitation yet, but the attack vector is remote via the web interface – it is inferred that an attacker could supply a crafted screenID. The combination of high severity and potential ease of exploitation makes the risk significant and warrants timely mitigation.

Generated by OpenCVE AI on September 30, 2026 at 10:47 UTC.

Remediation

Vendor Solution

Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security


OpenCVE Recommended Actions

  • Upgrade Toptech Systems TMS7 and TopHAT to version 7.8 or later to apply the vendor‑supplied fix
  • Restrict access to the manual transactions feature using role‑based controls so only authorized personnel can supply the screenID parameter
  • Implement input validation on screenID, allowing only numeric values, and monitor for abnormal query latency that may indicate injection attempts

Generated by OpenCVE AI on September 30, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
Title Toptech TMS7 and TopHAT SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-30T15:28:14.845Z

Reserved: 2026-08-10T17:31:09.969Z

Link: CVE-2026-68068

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T22:17:15.100

Modified: 2026-09-30T16:46:43.953

Link: CVE-2026-68068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T11:00:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')