PT-2026-68899 · Teamdavid · Teamdavid
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
A memory leak in the Webbox component allows an unauthorized actor to read sensitive information, including user passwords. This occurs when the application responds with memory contents upon accessing the endpoint "/.well-known/mta-sts.". An attacker can retrieve this data by making repeated requests to the endpoint without requiring authentication.
Recommendations
Update TeamDavid to a version later than Rollout 524.
As a temporary mitigation, restrict access to the "/.well-known/mta-sts." endpoint.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamdavid