CVE-2026-54208
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
07/08/2026
Last modified:
07/08/2026
Description
Tobit Laboratories AG TeamDavid&#39;s Webbox application is vulnerable to arbitrary file write, allowing an <br />
unauthenticated attacker to create or write into existing files on the <br />
server with attacker-controlled content. This is possible because user <br />
input is written directly to files without proper validation or <br />
restriction on file types. As a result, an attacker can create files <br />
(e.g., .htm), containing malicious JavaScript code. When a user accesses<br />
a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH



