Description
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An
attacker can send an email containing malicious JavaScript code. When a
user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that can execute arbitrary JavaScript in users’ browsers
Action: Patch
AI Analysis

Impact

TeamDavid’s Webbox application is vulnerable to a stored cross‑site scripting flaw. An attacker can send an email containing malicious JavaScript code, and when a user accesses that email, the injected code runs in the user’s browser session. This allows the attacker to steal credentials, hijack sessions, or carry out other client‑side attacks. The weakness is a form of improper input validation.

Affected Systems

The issue afflict Tobit Laboratories AG’s TeamDavid webbox product. It affects releases identified as before Rollout 528. The reported patches are only available for newer rollouts; any deployment still on an older version remains vulnerable.

Risk and Exploitability

The CVSS score of 5.3 suggests a medium severity. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit requires the attacker to send a malicious email that the victim subsequently opens, the attack vector is likely remote via user interaction. The impact is limited to client‑side compromise unless the attacker can also influence server‑side code execution.

Generated by OpenCVE AI on September 7, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Rollout 528 or later, which disables the vulnerable functionality by default.
  • Configure the application to encode or escape user‑supplied email content before rendering, to prevent script execution.
  • Implement a strict Content Security Policy on the TeamDavid web application to disallow inline script execution and restrict allowed script sources.

Generated by OpenCVE AI on September 7, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Fri, 07 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Stored XSS in web application
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T13:02:59.417Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54217

cve-icon Vulnrichment

Updated: 2026-08-07T11:23:31.591Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:59.027

Modified: 2026-09-07T14:16:52.947

Link: CVE-2026-54217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:15:17Z

Weaknesses
  • CWE-20

    Improper Input Validation