CVE-2024-13971: Lobster-World Lobster Pro
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
Affected products
- Lobster-World Lobster Pro: before 4.12.6-ga (fixed in 4.12.6-ga)
Published 2026-04-30. Last modified 2026-06-17.