CVE-2024-13971

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lobster-world:lobster_pro:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-30 13:16

Updated : 2026-06-17 07:03


NVD link : CVE-2024-13971

Mitre link : CVE-2024-13971

CVE.ORG link : CVE-2024-13971


JSON object : View

Products Affected

lobster-world

  • lobster_pro
CWE
CWE-611

Improper Restriction of XML External Entity Reference