CyberRota Analysis
AI-GeneratedThe open redirect vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows attackers to manipulate the "replyUrl" parameter, redirecting users to arbitrary third-party sites. This can facilitate phishing attacks, as users may be misled into believing they are navigating to a trusted domain. Organizations using TeamDavid, particularly those on Rollout 524, should prioritize addressing this vulnerability to protect their users from potential phishing threats.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.