High severityNVD Advisory· Published Aug 7, 2026
CVE-2026-54208
CVE-2026-54208
Description
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-controlled content. This is possible because user input is written directly to files without proper validation or restriction on file types. As a result, an attacker can create files (e.g., .htm), containing malicious JavaScript code. When a user accesses a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=Rollout 524
- Range: <=Rollout 524
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.