File Upload Vulnerability in TMS by TopTech
CVE-2026-70356
9.4CRITICAL
What is CVE-2026-70356?
The file upload functionality in TMS does not adequately validate the types of files being uploaded. This weakness enables an attacker to upload and potentially execute malicious PHP files on the server, which could lead to unauthorized access or control over the affected web application. It is crucial for users to apply security updates and review file upload validation mechanisms to mitigate these risks.
Affected Version(s)
TMS7 7.6.3
TopHAT 7.6.3
TMS7 7.8
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sachin Shetty and Roy Duisters of Shell CyberDefence reported this vulnerability to Toptech and CISA.
