PT-2026-102905 · Toptech Systems · Tms7+1

CVE-2026-71189

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
An attacker can construct a request that, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71189

Affected Products

Tms7
Tophat