PT-2026-68910 · Teamdavid · Teamdavid
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
The Webbox application is susceptible to HTTP header injection via the
cType URL parameter. The application fails to properly restrict control characters, such as colons or URL-encoded newlines (%0a), allowing the modification of the Content-Type header in HTTP responses. This flaw enables attackers to inject additional headers, such as extra Location headers, which can lead to an open redirect.Recommendations
Update TeamDavid to a version later than Rollout 524.
As a temporary mitigation, restrict or sanitize the use of the
cType parameter in URL requests.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamdavid