PT-2026-68904 · Teamdavid · Teamdavid
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
The Webbox application allows an unauthenticated attacker to create or modify files on the server using attacker-controlled content. This occurs because user input is written directly to files without adequate validation or restrictions on file types. An attacker can exploit this to create files, such as .htm files, containing malicious JavaScript, which leads to stored cross-site scripting (XSS) when a user accesses the created file.
Recommendations
Update TeamDavid to a version later than Rollout 524.
Fix
RCE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teamdavid