CVE-2026-54217 Details
Description
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
A stored cross-site scripting vulnerability has been identified in Tobit Laboratories AG TeamDavid's Webbox application, affecting versions through Rollout 524. This vulnerability allows an attacker to send an email containing malicious JavaScript. When the recipient accesses the email, the script executes, potentially leading to unauthorized actions or data exposure.
Users are advised to update to the latest version of TeamDavid, as the most recent release appears to address this vulnerability. For organizations, consider placing the TeamDavid web server behind a VPN or reverse proxy that filters requests and blocks access to non-essential endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | CISA-ADP | BundleRemedyTechnical Analysis |
| https://chayns.net/77892-10814/tapp/763210?postId=11454 | [email protected] | |
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | [email protected] | BundleRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tobit Laboratories AG TeamDavid | <= 524 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 7, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion