CVE-2026-68954

Summary

The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.

Affected Software

VendorProductVersion RangeStatus
Toptech SystemsTMS77.6.3affected
Toptech SystemsTMS77.8unaffected
Toptech SystemsTopHAT7.6.3affected
Toptech SystemsTopHAT7.8unaffected

Weaknesses

  • CWE-89: CWE-89

References