Impact
The vulnerability originates from an unsanitized "pathnameroot" parameter in TeamDavid’s web search feature, allowing an unauthenticated attacker to supply UNC paths (e.g., "\\\\Server\\Share"). The server will then attempt to connect to the specified SMB endpoint, potentially authenticating with NTLM and exposing NTLM hashes. This is a classic Server‑Side Request Forgery that can lead to credential theft or SMB relay attacks. The high CVSS score of 7.7 reflects the potential for serious impact, and the lack of an EPSS figure indicates that the current exploitation probability is unknown but the flaw remains available.
Affected Systems
Affected systems The flaw is present in Tobit Laboratories AG’s TeamDavid platform, specifically from Rollout 524 onward. No earlier rollouts are known to be impacted, but the issue is documented only for this version series.
Risk and Exploitability
Risk and exploitability The attack vector is straightforward: any user can trigger the SSRF by submitting a crafted search request containing a UNC path. No authentication is required, and if outbound SMB connections are permitted, attackers can use the server as a relay or harvest NTLM credentials. While the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the CVSS rating and the nature of the flaw suggest a moderate to high risk that should be mitigated promptly.
OpenCVE Enrichment