IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Toptech TMS7 and TopHAT

CRITICAL
CVSS 10.0
Date 2026-09-29T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.

// Vulnerabilities (10)

CVE ID CVSS Score Severity Description
CVE-2026-63713 9.0 critical
The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.
CVE-2026-68068 9.0 critical
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
CVE-2026-70356 9.1 critical
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
CVE-2026-71189 3.5 low
An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.
CVE-2026-71379 10.0 critical
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
CVE-2026-72507 9.0 critical
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
CVE-2026-69662 3.7 low
The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.
CVE-2026-71302 7.1 high
The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
CVE-2026-72510 9.0 critical
The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
CVE-2026-68954 9.0 critical
The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.

// Remediations (1)

Mitigation: Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been
Toptech Systems sent a security advisory to their customers on July 20, 2026. The issues have been addressed in release 7.8. Users can get the latest release and more information on these issues, at the Toptech Systems security blog.

// References