CVE-2026-72510

Summary

The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.

Affected Software

VendorProductVersion RangeStatus
Toptech SystemsTMS77.6.3affected
Toptech SystemsTMS77.8unaffected
Toptech SystemsTopHAT7.6.3affected
Toptech SystemsTopHAT7.8unaffected

Weaknesses

  • CWE-89: CWE-89

References