CVE-2024-13971
EUVD-2024-5556330.04.2026, 13:16
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lobster-world | lobster_pro | 𝑥 < 4.12.6-ga |
𝑥
= Vulnerable software versions