Description
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET requests to arbitrary services.
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
Any version before 4.12.6-GA
4.12.6-GA (custom)
Timeline
| 2024-08-12: | Initial contact with vendor |
| 2024-08-14: | Vulnerability reported to vendor |
| 2024-08-14: | CVE ID requested |
| 2024-08-22: | Initial feedback received from vendor: unable to reproduce |
| 2024-08-28: | Vulnerability demonstrated in vendor's "Community server" |
| 2024-09-19: | Vulnerability reported fixed by vendor in Lobster_pro release 4.12.6-GA |
| 2025-07-03: | Reserved CVE ID CVE-2024-13971 |
| 2026-04-30: | Advisory released |
Credits
Marcelo Reyes of SCHUTZWERK GmbH
References
www.schutzwerk.com/en/blog/schutzwerk-sa-2024-005/