Impact
TeamDavid’s Webbox application is vulnerable to a stored cross‑site scripting flaw. An attacker can send an email containing malicious JavaScript code, and when a user accesses that email, the injected code runs in the user’s browser session. This allows the attacker to steal credentials, hijack sessions, or carry out other client‑side attacks. The weakness is a form of improper input validation.
Affected Systems
The issue afflict Tobit Laboratories AG’s TeamDavid webbox product. It affects releases identified as before Rollout 528. The reported patches are only available for newer rollouts; any deployment still on an older version remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 suggests a medium severity. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit requires the attacker to send a malicious email that the victim subsequently opens, the attack vector is likely remote via user interaction. The impact is limited to client‑side compromise unless the attacker can also influence server‑side code execution.
OpenCVE Enrichment