PT-2026-68896 · Tobit Laboratories Ag · Teamdavid
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
Tobit Laboratories AG TeamDavid's Webbox contains a local file inclusion issue within the functionality used to send emails, faxes, and SMS. An authenticated user can attach files to a message by using the
@@attach command in the scjob form field. Although a filter exists to restrict access to the user folder and the David config folder, it can be bypassed using an alternate data stream. This allows the unauthorized download of sensitive information, including the server's private key and access files containing passwords of other users.Recommendations
Update TeamDavid to a version later than Rollout 524.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamdavid