Local File Inclusion Vulnerability in TeamDavid's Webbox by Tobit Laboratories AG
CVE-2026-54200
8.4HIGH
What is CVE-2026-54200?
TeamDavid's Webbox, developed by Tobit Laboratories AG, has a local file inclusion vulnerability that can be exploited through the application's messaging functionality. Users are able to attach files to messages by using the '@@attach' command within the 'scjob' form field. While the application implements a filter to restrict access to sensitive directories, an alternate data stream can be leveraged to bypass this filter. This opens the possibility for authenticated users to download potentially sensitive files, including other users' credentials and critical server information.
Affected Version(s)
TeamDavid 0
