CVE-2026-54208

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
07/08/2026
Last modified:
07/08/2026

Description

Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application is vulnerable to arbitrary file write, allowing an <br /> unauthenticated attacker to create or write into existing files on the <br /> server with attacker-controlled content. This is possible because user <br /> input is written directly to files without proper validation or <br /> restriction on file types. As a result, an attacker can create files <br /> (e.g., .htm), containing malicious JavaScript code. When a user accesses<br /> a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.