Impact
The vulnerability arises from the use of unsafe functions that allow execution of inline scripts and string evaluation. This lack of input sanitization enables arbitrary code to run within the application, potentially providing an attacker with the ability to execute malicious scripts. The weakness aligns with CWE-95 and could compromise the confidentiality, integrity and availability of the system if exploited.
Affected Systems
Affected systems include Toptech Systems' TMS7 and TopHAT products. Versions prior to 7.8 are vulnerable; the issue was addressed in the 7.8 release. Administrators should verify the current version of these applications and plan an upgrade.
Risk and Exploitability
The CVSS score of 2.1 indicates low overall severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting limited known exploitation. However, the lack of input validation and use of eval functions present a theoretical attack path, especially if an attacker can supply trusted input or manipulate configuration files. Based on the description, it is inferred that the attack vector may involve a trusted user or an administrator who can supply data that is processed by the unsafe functions.
OpenCVE Enrichment