PT-2026-102907 · Toptech · Tms7
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Toptech TMS7 versions prior to 7.8
Description
An unauthenticated attacker can export arbitrary database tables by sending a crafted POST request to the file export endpoint.
Recommendations
Upgrade Toptech TMS7 to version 7.8.
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tms7