Impact
TeamDavid’s Webbox application is vulnerable to a stored cross‑site scripting flaw. An attacker can embed malicious JavaScript into an email, and when a user opens that email the injected code runs in the user’s browser session. This allows the attacker to steal credentials, hijack sessions, or carry out other client‑side attacks. The weakness is a form of improper input validation.
Affected Systems
The issue afflict Tobit Laboratories AG’s TeamDavid webbox product. It affects releases identified as Rollout 524 and earlier. The reported patches are only available for newer rollouts; any deployment still on Rollout 524 or an older version remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 suggests a medium severity. The EPSS score is missing, so the current availability of exploit scripts is unknown. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit requires the attacker to send a malicious email that the victim subsequently opens, the attack vector is likely remote via user interaction. The impact is limited to client‑side compromise unless the attacker can also influence server‑side code execution.
OpenCVE Enrichment