Impact
The vulnerability exists in the 'reportType' parameter of the product summary report feature within the balancing reports section. The time‑based blind SQL injection allows an attacker to execute arbitrary SQL commands against the underlying database, which can lead to extraction of sensitive data and potentially aggravate the impact if the attacker escalates privileges. This flaw is categorized as CWE-89.
Affected Systems
The flaw affects Toptech Systems’ TMS7 and TopHAT products. No specific affected versions are listed in the advisory, but the vendor’s patch notes indicate that release 7.8 resolves the issue for TMS7, and the same fix is likely applicable to TopHAT. Systems running earlier releases are at risk.
Risk and Exploitability
The severity is marked with a CVSS score of 8.5, indicating a high‑severity attack. The exploit is likely carried out via a remote web interface that accepts the 'reportType' input, and it requires the attacker to send crafted requests that trigger timed delays. While EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, the high CVSS score and the nature of the input vector suggest that the risk of exploitation remains significant if the affected endpoint is exposed.
OpenCVE Enrichment