NONE · 0

CVE-2026-54208

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-co...

Vulnerability Description

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-controlled content. This is possible because user input is written directly to files without proper validation or restriction on file types. As a result, an attacker can create files (e.g., .htm), containing malicious JavaScript code. When a user accesses a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-54208?

CVE-2026-54208 is a documented vulnerability. Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-co...

How severe is CVE-2026-54208?

CVSS scoring is not yet available for CVE-2026-54208. Check NVD for updates.

Is there a patch for CVE-2026-54208?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.