CVE-2024-13971
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
View on NVDAnalysis
Lobster_pro versions before 4.12.6-GA are vulnerable to an unauthenticated XML External Entity (XXE) flaw. Attackers can exploit this to read sensitive files from the host server or perform SSRF attacks to probe internal network services.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NCWE-611EPSS
Affects
lobster-world:lobster_proTechnical description
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.