Impact
Tobit Laboratories AG TeamDavid’s Webbox is vulnerable to HTTP header injection through the request body in its link storing functionality. An attacker who supplies a line feed in the request body can cause that character to be appended to the redirect target in the 302 HTTP response. This grants the attacker control over the response headers, allowing manipulation of the redirect behavior or other header values.
Affected Systems
The vulnerability affects all TeamDavid releases through Rollout 524. The affected vendor is Tobit Laboratories AG. No additional version details are provided beyond the rollout identifier.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation cannot be quantified. The issue is not listed in the CISA KEV catalog. Likely attack vectors require the ability to send crafted HTTP requests to the link storing endpoint; if that endpoint is exposed externally, the vulnerability can be triggered. Given these conditions, the risk is considered moderate.
OpenCVE Enrichment