{"id":"CVE-2026-72507","published":"2026-09-29T22:18:22.437","lastModified":"2026-09-29T22:18:22.437","description":"The \"reportType\" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.","cvssScore":9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","tags":[]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-02","tags":[]},{"url":"https://www.toptech.com/blog/tms7-version-7-8-strengthens-security","tags":[]}],"exploitRefs":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-272-02.json","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw is a time-based blind SQL injection vulnerability in the 'reportType' parameter, allowing attackers to inject malicious SQL queries and potentially gain unauthorized access or manipulate data. This matters because it can lead to severe data breaches and system compromise.","exploitability":"Exploitation requires knowledge of the specific SQL injection technique and access to the 'reportType' parameter. Precondition is that the feature is enabled and the application is not properly sanitized.","blast_radius":"If exploited, this vulnerability could lead to data theft, unauthorized data manipulation, and potential system compromise affecting users and operations.","remediation":"Disable the affected feature or restrict access to the 'reportType' parameter until a patch is available.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["sql-injection","blind-sql","web","data-breach"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:00:10.001Z"}}