GHSA-pfmg-m2fv-v732Medium

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the ...

Published
August 7, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link, resulting in the ability to control the response headers. This issue affects TeamDavid through Rollout 524.

🔗 References (4)