Impact
The vulnerability arises because the application accepts session identifiers supplied by the user and fails to regenerate a new session ID after authentication. This behavior allows an attacker to predefine a session ID, have a victim authenticate, and then reuse that same ID. The result is a thorough session takeover, enabling an attacker to assume the victim’s identity and access protected resources with the victim’s privileges.
Affected Systems
The flaw affects Toptech Systems’ TMS7 and TopHAT products. No specific affected versions are cited beyond the mention that the issue is resolved in release 7.8, implying that all earlier releases could be vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation in the wild. The probable attack path requires the attacker to deliver a crafted request containing a chosen session identifier before the victim logs in, usually via the web interface or API. Defenses rely on server‑side session regeneration and input validation to prevent session fixation.
OpenCVE Enrichment