Security Advisory

CVE-2024-13971

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-30 12:11:46
Last updated 2026-05-17 22:18:37
Assigner SCHUTZWERK
CVSS score 7.7
State PUBLISHED

Description

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.