PT-2026-68910 · Teamdavid · Teamdavid

·

CVE-2026-54214

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions TeamDavid versions prior to Rollout 525
Description The Webbox application is susceptible to HTTP header injection via the cType URL parameter. The application fails to properly restrict control characters, such as colons or URL-encoded newlines (%0a), allowing the modification of the Content-Type header in HTTP responses. This flaw enables attackers to inject additional headers, such as extra Location headers, which can lead to an open redirect.
Recommendations Update TeamDavid to a version later than Rollout 524. As a temporary mitigation, restrict or sanitize the use of the cType parameter in URL requests.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54214

Affected Products

Teamdavid