CVE-2026-54199
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-20
Validación incorrecta de entrada
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026
Descripción
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&#39;s Webbox is vulnerable to HTTP header injection through the <br />
request body in the application&#39;s link storing functionality <br />
(//ServerClient_celink.htm), which is appended to the redirect target in<br />
the 302 HTTP response. If a line feed is added, this will also be added<br />
to the redirect link, resulting in the ability to control the response <br />
headers. This issue affects TeamDavid through Rollout 524.
Impacto
Puntuación base 4.0
5.30
Gravedad 4.0
MEDIA



