Critical9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

PT-2025-67: XML external entity leads to Local File Read and Server-side request forgery in FastReport.NET

Error type:

  • CWE-611:Improper Restriction of XML External Entity Reference

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
  • Severity (CVSSv4.0): 9.2 (Critical)

Description:

The vulnerability was identified in FastReport .NET, versions 2024.2.20.

The discovered vulnerability, due to the ability to inject and expand external entities, can be exploited by an attacker to read arbitrary local files and perform server‑side request forgery (SSRF) with full response retrieval.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 04.07.2025

Recommendations:

  • Update to version 2025.2.6 or higher

Additional information: Release notes

Researcher: Dmitry Prokhorov (Positive Technologies)

Identifiers:

BDU:2025-08867

Vendor:

Fast Reports Inc.

Vulnerable product:

FastReport.NET

Vulnerable versions:

2024.2.20