CVE-2026-54208
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-20
Validación incorrecta de entrada
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026
Descripción
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&#39;s Webbox application is vulnerable to arbitrary file write, allowing an <br />
unauthenticated attacker to create or write into existing files on the <br />
server with attacker-controlled content. This is possible because user <br />
input is written directly to files without proper validation or <br />
restriction on file types. As a result, an attacker can create files <br />
(e.g., .htm), containing malicious JavaScript code. When a user accesses<br />
a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Impacto
Puntuación base 4.0
8.50
Gravedad 4.0
ALTA



