Vulnerability vector:
- Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
- Severity (CVSSv4.0): 9.2 (Critical)
Description:
The vulnerability was identified in FastReport .NET, versions 2024.2.20.
The discovered vulnerability, due to the ability to inject and expand external entities, can be exploited by an attacker to read arbitrary local files and perform server‑side request forgery (SSRF) with full response retrieval.
Vulnerability status: Confirmed by vendor
Date of vulnerability remediation: 04.07.2025
Recommendations:
- Update to version 2025.2.6 or higher
Additional information: Release notes
Researcher: Dmitry Prokhorov (Positive Technologies)