Description
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An
attacker can send an email containing malicious JavaScript code. When a
user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

TeamDavid’s Webbox application is vulnerable to a stored cross‑site scripting flaw. An attacker can embed malicious JavaScript into an email, and when a user opens that email the injected code runs in the user’s browser session. This allows the attacker to steal credentials, hijack sessions, or carry out other client‑side attacks. The weakness is a form of improper input validation.

Affected Systems

The issue afflict Tobit Laboratories AG’s TeamDavid webbox product. It affects releases identified as Rollout 524 and earlier. The reported patches are only available for newer rollouts; any deployment still on Rollout 524 or an older version remains vulnerable.

Risk and Exploitability

The CVSS score of 5.3 suggests a medium severity. The EPSS score is missing, so the current availability of exploit scripts is unknown. The vulnerability is not listed in CISA’s KEV catalog. Because the exploit requires the attacker to send a malicious email that the victim subsequently opens, the attack vector is likely remote via user interaction. The impact is limited to client‑side compromise unless the attacker can also influence server‑side code execution.

Generated by OpenCVE AI on August 7, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TeamDavid to the latest Rollout, which includes a fix that sanitizes email content before rendering.
  • Configure TeamDavid to encode or escape all user‑supplied email content prior to storage and display, thereby preventing script execution.
  • Implement a strict Content Security Policy on the TeamDavid web application to disallow inline script execution and restrict allowed script sources.

Generated by OpenCVE AI on August 7, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Stored XSS in web application
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-08-07T11:23:53.681Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54217

cve-icon Vulnrichment

Updated: 2026-08-07T11:23:31.591Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T11:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation