Description
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
Published: 2026-09-29
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Blind SQL injection can lead to data exposure and potential exploitation of confidential business data
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the 'reportType' parameter of the product summary report feature within the balancing reports section. The time‑based blind SQL injection allows an attacker to execute arbitrary SQL commands against the underlying database, which can lead to extraction of sensitive data and potentially aggravate the impact if the attacker escalates privileges. This flaw is categorized as CWE-89.

Affected Systems

The flaw affects Toptech Systems’ TMS7 and TopHAT products. No specific affected versions are listed in the advisory, but the vendor’s patch notes indicate that release 7.8 resolves the issue for TMS7, and the same fix is likely applicable to TopHAT. Systems running earlier releases are at risk.

Risk and Exploitability

The severity is marked with a CVSS score of 8.5, indicating a high‑severity attack. The exploit is likely carried out via a remote web interface that accepts the 'reportType' input, and it requires the attacker to send crafted requests that trigger timed delays. While EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, the high CVSS score and the nature of the input vector suggest that the risk of exploitation remains significant if the affected endpoint is exposed.

Generated by OpenCVE AI on September 30, 2026 at 10:21 UTC.

Remediation

Vendor Solution

Toptech Systems sent a security advisory to their customers on July 20, 2026. The issue has been addressed in release 7.8. Users can get the latest release and more information on this issue at the Toptech Systems security blog. https://www.toptech.com/blog/tms7-version-7-8-strengthens-security


OpenCVE Recommended Actions

  • Update to Toptech Systems release 7.8, which contains the fix for the SQL injection flaw.
  • Restrict access to the balancing reports endpoint, ensuring only authenticated and authorized users or systems can send requests to the 'reportType' parameter.
  • Deploy a web application firewall or input‑validation rule to detect and block suspicious SQL injection patterns, particularly time‑based blind injection attempts.

Generated by OpenCVE AI on September 30, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
Title Toptech TMS7 and TopHAT SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-30T15:28:14.706Z

Reserved: 2026-08-10T17:31:09.965Z

Link: CVE-2026-72507

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T22:18:22.437

Modified: 2026-09-30T16:46:43.953

Link: CVE-2026-72507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T10:30:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')