Impact
An attacker can construct a request that, when sent on behalf of another user, injects arbitrary JavaScript into the victim’s browser session. The script executes with the victim’s privileges, enabling actions such as session hijacking, data theft, or UI manipulation. The vulnerability reflects a classic XSS flaw and is classified as CWE‑79.
Affected Systems
The flaw affects Toptech Systems products TMS7 and TopHAT. All releases prior to version 7.8 are vulnerable; the security advisory states that the issue is resolved in release 7.8 and later. Users running older versions should upgrade to a fixed build.
Risk and Exploitability
CVSS score of 4.8 indicates moderate severity. EPSS is not available, so exploitation likelihood is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires an attacker to send a crafted request on behalf of an authenticated user, suggesting the threat vector is through legitimate user sessions. While the impact is client‑side, the ability to execute arbitrary code in a user’s context remains a significant concern for data confidentiality and session integrity.
OpenCVE Enrichment