Impact
TeamDavid Webbox is vulnerable to an arbitrary file deletion flaw that allows a malicious actor to delete files on the underlying server. By submitting a malicious value for the form field scjob that contains the @@COMMENTFILE command, the software interprets that value and executes a delete operation on any file accessible to the Webbox process. This results in loss of data, service disruption, and potential integrity compromise. The flaw exists in releases before Rollout 528.
Affected Systems
The vulnerability affects Tobit Laboratories AG TeamDavid Webbox versions released prior to Rollout 528. Any installation that uses the email, fax, SMS, or other send‑functionality, which relies on the scjob field, is susceptible. Starting with Rollout 528 the functionality is disabled by default, eliminating the exposure for newer releases.
Risk and Exploitability
The CVSS v3.1 score of 8.4 classifies this as a high‑severity issue. The vulnerability can be triggered through an HTTP request to the Webbox endpoint, so network connectivity to the system is sufficient for exploitation. Authentication requirements are not specified in the vendor documentation; therefore we infer that the endpoint might be reachable by authenticated users or potentially even anonymous traffic, though this is not confirmed. The EPSS score is less than 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the ability to delete arbitrary files remotely poses a severe risk to affected deployments until the software is updated to Rollout 528 or later.
OpenCVE Enrichment