Vulnerability Description
Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter “!templateName=entryMail”, an attacker can cause the payload to execute in the victim’s browser when they click the link. This issue affects TeamDavid through Rollout 524.
Related Weaknesses (CWE)
References
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
FAQ
What is CVE-2026-54216?
CVE-2026-54216 is a documented vulnerability. Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or...
How severe is CVE-2026-54216?
CVSS scoring is not yet available for CVE-2026-54216. Check NVD for updates.
Is there a patch for CVE-2026-54216?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.