Medium severityNVD Advisory· Published Aug 7, 2026· Updated Sep 7, 2026
CVE-2026-54216
CVE-2026-54216
Description
Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter “!templateName=entryMail”, an attacker can cause the payload to execute in the victim’s browser when they click the link. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: < Rollout 528
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.