Security Advisory

CVE-2026-54216

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-07 09:48:46
Last updated 2026-08-07 11:24:31
Assigner NCSC.ch
CVSS score not scored
State PUBLISHED

Description

Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter “!templateName=entryMail”, an attacker can cause the payload to execute in the victim’s browser when they click the link. This issue affects TeamDavid through Rollout 524.