Critical severity9.8NVD Advisory· Published Oct 29, 2020· Updated Jun 17, 2026
CVE-2020-27998
CVE-2020-27998
Description
An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
FastReport.OpenSourceNuGet | < 2020.4.0 | 2020.4.0 |
Affected products
3- FastReport/FastReportdescription
Patches
Vulnerability mechanics
References
6- securitylab.github.com/advisories/GHSL-2020-143-FastReportsInc-FastReportsnvdExploitThird Party AdvisoryADVISORY
- github.com/FastReports/FastReport/compare/v2020.3.0...v2020.4.0nvdThird Party AdvisoryWEB
- github.com/FastReports/FastReport/pull/206nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-v726-3vg9-cp34ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-27998ghsaADVISORY
- opensource.fast-report.com/2020/09/report-script-security.htmlnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.