Vulnerability Description
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lobster-World | Lobster Pro | < 4.12.6-ga |
Related Weaknesses (CWE)
References
- https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-005/ExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2026/May/1
FAQ
What is CVE-2024-13971?
CVE-2024-13971 is a vulnerability with a CVSS score of 7.5 (HIGH). Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server an...
How severe is CVE-2024-13971?
CVE-2024-13971 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-13971?
Check the references section above for vendor advisories and patch information. Affected products include: Lobster-World Lobster Pro.