What is CVE-2026-54217?
CVE-2026-54217 is a stored XSS vulnerability in Tobit Laboratories AG's TeamDavid Webbox application, where an attacker can send an email containing malicious JavaScript. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects versions through Rollout 524, and applying the security patch is recommended.
Azərbaycanca: CVE-2026-54217, Tobit Laboratories AG-nin TeamDavid Webbox tətbiqində aşkar edilmiş saxlanılan XSS (Stored Cross-Site Scripting) zəifliyidir. Təcavüzkar zərərli JavaScript kodu olan e-poçt göndərərək, istifadəçi həmin e-poçtu açdıqda kodun işə düşməsinə səbəb ola bilər. Bu problem Rollout 524 daxil olmaqla məhsul versiyalarına təsir edir, dərhal təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Tobit Laboratories AG
FAQ2
Which versions of the TeamDavid Webbox application are affected by CVE-2026-54217?
CVE-2026-54217 affects TeamDavid Webbox versions through Rollout 524.
How can an attacker exploit the CVE-2026-54217 vulnerability?
An attacker can exploit the vulnerability by sending an email containing malicious JavaScript. The stored XSS is triggered when a user opens the email.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.