Impact
Tobit Laboratories AG TeamDavid's Webbox component contains a local file inclusion flaw triggered by the 'scjob' form field. The flaw allows an attacker with access to the send‑message interface to inject an '@@attach' command that overrides the intended file path. By exploiting the alternate data stream bypass, the attacker can download arbitrary files from the server, including user credentials and the system private key. This vulnerability can lead to disclosure of confidential information and potentially compromise the entire system.
Affected Systems
The flaw affects all TeamDavid releases up to Rollout 524, inclusive. Users running Tobit Laboratories AG TeamDavid prior to upgrading beyond Rollout 524 are therefore vulnerable. The affected component is the Webbox send‑email/fax/SMS interface.
Risk and Exploitability
The CVSS base score is 8.4, classifying it as High severity. Because an authenticated user needs to trigger the upload request, the threat is primarily internal; however, any user with permissions to use the messaging functions can download arbitrary files, a scenario that would suffice for an attacker with the required privileges. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, so public exploitation references are currently limited. Nonetheless, the existence of a direct path to sensitive files increases the potential impact considerably.
OpenCVE Enrichment