Impact
Tobit Laboratories AG TeamDavid's Webbox component contains a local file inclusion flaw triggered by the "scjob" form field. By specifying an "@@attach" command, an authenticated user can override the intended file path and supply an alternate data stream, allowing the server to bypass its file‑path restrictions. This bypass enables the download of arbitrary files, including other users' credential files and the server's private key, thereby exposing confidential information.
Affected Systems
The flaw applies to all TeamDavid releases before Rollout 528, which were released prior to June 30, 2026. Users of Tobit Laboratories AG’s TeamDavid are vulnerable through the Webbox send‑email/fax/SMS interface. Starting with Rollout 528, the affected functionality is disabled by default, removing this exposure for newer releases.
Risk and Exploitability
The CVSS base score of 8.4 classifies this vulnerability as High severity. The attack requires an authenticated user, and the description indicates that it is likely a user with messaging privileges who submits a crafted "scjob" value containing "@@attach", causing the server to serve the requested file. The EPSS score is < 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability to download any file the attacker selects represents a significant risk for impacted installations.
OpenCVE Enrichment