CVE-2026-70356

Summary

The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.

Affected Software

VendorProductVersion RangeStatus
Toptech SystemsTMS77.6.3affected
Toptech SystemsTMS77.8unaffected
Toptech SystemsTopHAT7.6.3affected
Toptech SystemsTopHAT7.8unaffected

Weaknesses

  • CWE-434: CWE-434

References