CVE-2024-13971
Arbitrary File Read and Server Side Request Forgery via XML External Entities in Lobster_pro
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
| CWE | CWE-611 |
| Vendor | lobster gmbh |
| Product | lobster_pro |
| Published | Apr 30, 2026 |
| Last Updated | Apr 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for lobster gmbh lobster_pro
Be the first to know when new unknown vulnerabilities affecting lobster gmbh lobster_pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Lobster GmbH / Lobster_pro
0 < 4.12.6-GA
References
Credits
Marcelo Reyes of SCHUTZWERK GmbH