CVE-2026-68068

Summary

The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.

Affected Software

VendorProductVersion RangeStatus
Toptech SystemsTMS77.6.3affected
Toptech SystemsTMS77.8unaffected
Toptech SystemsTopHAT7.6.3affected
Toptech SystemsTopHAT7.8unaffected

Weaknesses

  • CWE-89: CWE-89

References