CVE-2026-54216

EUVD-2026-54447
Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) 
vulnerability. By sending a specially crafted link including an 
arbitrary path, an XSS payload or the parameter “EntryInfo”, and the 
parameter “!templateName=entryMail”, an attacker can cause the payload 
to execute in the victim’s browser when they click the link. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---