Local File Inclusion Vulnerability in TeamDavid's Webbox by Tobit Laboratories AG
CVE-2026-54200

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54200?

TeamDavid's Webbox, developed by Tobit Laboratories AG, has a local file inclusion vulnerability that can be exploited through the application's messaging functionality. Users are able to attach files to messages by using the '@@attach' command within the 'scjob' form field. While the application implements a filter to restrict access to sensitive directories, an alternate data stream can be leveraged to bypass this filter. This opens the possibility for authenticated users to download potentially sensitive files, including other users' credentials and critical server information.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weiss of InfoGuard Labs
.