Impact
TeamDavid's Webbox contains an input validation flaw that allows a malicious user to delete arbitrary files on the underlying server. By submitting a value for the form field scjob that includes the special @@COMMENTFILE command, the software interprets the parameter as a file deletion instruction, removing any file accessible to the webbox process. The effect is loss of data, potential service disruption, and integrity compromise.
Affected Systems
The vulnerability affects the Tobit Laboratories AG TeamDavid Webbox component released before Rollout 524. Any installation of TeamDavid that uses the send‑email, fax, and SMS features – which rely on the scjob form field – is susceptible. Consequently, older versions of TeamDavid Webbox remain at risk until updated to Rollout 524 or later.
Risk and Exploitability
The CVSS v3.1 score of 8.4 marks this as a high‑severity issue. Because the flaw can be triggered through an HTTP request to the Webbox endpoint, an attacker with network connectivity to the system can craft a request containing a malicious scjob value. Authentication requirements are not detailed in the vendor description; therefore the possibility exists that the endpoint is accessible to authenticated users or, in a worse case, to anonymous traffic. Although EPSS data is unavailable and the vulnerability is not in the CISA KEV catalog, the destructive impact and remote trigger make this problem a high risk to affected deployments.
OpenCVE Enrichment