PT-2026-68911 · Tobit Laboratories Ag · Teamdavid
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect issue. An attacker can craft a URL that redirects the user's browser to an arbitrary third-party site via the
replyUrl parameter. This can be leveraged for phishing attacks by using a trusted domain link to redirect users to a malicious website.Recommendations
Update to a version later than Rollout 524.
Avoid using the
replyUrl parameter until the update is applied.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamdavid