What is CVE-2026-54216?
This CVE identifies a Reflected Cross-Site Scripting (XSS) vulnerability in the TeamDavid Webbox application by Tobit Laboratories AG. An attacker can execute malicious scripts by crafting a link that utilizes the 'EntryInfo' parameter and the '!templateName=entryMail' parameter. Users should avoid clicking on untrusted links, and administrators must implement proper input sanitization.
Azərbaycanca: Bu CVE, Tobit Laboratories AG-nin TeamDavid Webbox tətbiqində aşkarlanmış Reflected Cross-Site Scripting (XSS) boşluğudur. Xüsusi hazırlanmış link vasitəsilə 'EntryInfo' parametri və '!templateName=entryMail' parametri istismar edilərək zərərli skript icra oluna bilər. Təsirlənən istifadəçilər naməlum linklərə daxil olmamalı, inzibatçılar isə daxil olan məlumatların təmizlənməsini təmin etməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Tobit Laboratories AG
FAQ2
Which parameters are exploited in CVE-2026-54216?
The 'EntryInfo' parameter and '!templateName=entryMail' parameter are exploited in this vulnerability.
Which application by Tobit Laboratories AG is affected by the CVE-2026-54216 Reflected XSS vulnerability?
The TeamDavid Webbox application is affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.