CVE-2026-54200
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026
Descripción
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&#39;s Webbox is vulnerable to a local file inclusion vulnerability in<br />
the send email, fax, SMS, etc. functionality. By specifying an &#39;@@attach&#39; command in the form field &#39;scjob&#39;, files can be attached to a message, <br />
which can then be downloaded by an authenticated user. A filter is in <br />
place that restricts access to the David con-fig folder and the user <br />
folder. However, this filter can be bypassed by specifying an alternate <br />
data stream, allowing the download of sensitive files such as other <br />
users&#39; access files containing their passwords or the server&#39;s private <br />
key. This issue affects TeamDavid through Rollout 524.
Impacto
Puntuación base 4.0
8.40
Gravedad 4.0
ALTA



