Impact
Tobit Laboratories AG’s TeamDavid Webbox application contains a reflected XSS flaw that is triggered when an attacker sends a link that includes a malicious payload in the EntryInfo parameter together with the !templateName=entryMail flag. The payload is reflected unescaped back to the victim’s browser and is executed with the privileges of the page, enabling script injection that can lead to data theft or session hijacking. This weakness is a classic example of CWE‑79, input not properly sanitized before being output.
Affected Systems
The vulnerability affects TeamDavid Webbox releases up to Rollout 524 published by Tobit Laboratories AG. Any installation of this version or earlier is vulnerable; later releases contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact level. No EPSS score is publicly available, and the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. However, the attack requires an end‑user to click a crafted link, so the vector is primarily social‑engineering or phishing. Once executed, the script runs in the victim’s context, potentially exfiltrating sensitive information or hijacking the session.
OpenCVE Enrichment