Descripción
The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP response. By using URL-encoded characters such as -%2e- (representing a dot), an attacker can manipulate the portion of the URL following the top-level domain (TLD). If a similar, registerable TLD exists (for example, if -.com- is the application-s domain, and -.company- is available for registration), an attacker can craft a URL to redirect users to a malicious -.company- domain. By using URL-encoded line feeds, it becomes possible to insert arbitrary response headers in the server-s HTTP response. This issue affects TeamDavid through Rollout 524.
CVSS 5.3EPSS 0.335%Riesgo 0.55
Ver fuente- Publicación
- 2026-08-07 10:16:56
- Última modificación
- 2026-08-10 12:17:13
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X