Impact
Tobit Laboratories AG’s TeamDavid Webbox application contains a reflected XSS flaw that is triggered when an attacker sends a specially crafted link that includes an arbitrary path, an XSS payload or the EntryInfo parameter together with the !templateName=entryMail flag. The payload is reflected unescaped back to the victim’s browser and is executed with the privileges of the page, enabling script injection that can lead to data theft or session hijacking. This weakness is a classic example of CWE‑79, input not properly sanitized before being output. Starting with Rollout 528, the affected functionality is disabled by default, so the vulnerability is no longer exposed through this functionality.
Affected Systems
The vulnerability affects TeamDavid Webbox releases up to Rollout 527 published by Tobit Laboratories AG. Any installation of Rollout 527 or earlier is vulnerable; later releases contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact level. The EPSS score is < 1%, indicating a low but nonzero probability of exploitation, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. However, the attack requires an end‑user to click a crafted link, so the vector is primarily social‑engineering or phishing. Once executed, the script runs in the victim’s context, potentially exfiltrating sensitive information or hijacking the session.
OpenCVE Enrichment