{"id":"CVE-2020-27998","aliases":["GHSA-v726-3vg9-cp34"],"url":"https://o3.security/vulnerability/CVE-2020-27998","summary":"Missing Authorization in FastReport","details":"An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.","published":"2020-10-29T18:15:12.787Z","modified":"2026-07-08T21:25:41.808287Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"NuGet","name":"FastReport.OpenSource","fixedVersion":"2020.4.0"}],"fix":{"url":"https://github.com/FastReports/FastReport/pull/206","label":"FastReports/FastReport#206"},"references":[{"type":"ADVISORY","url":"https://github.com/FastReports/FastReport/compare/v2020.3.0...v2020.4.0"},{"type":"ADVISORY","url":"https://github.com/FastReports/FastReport/pull/206"},{"type":"ADVISORY","url":"https://opensource.fast-report.com/2020/09/report-script-security.html"},{"type":"EVIDENCE","url":"https://securitylab.github.com/advisories/GHSL-2020-143-FastReportsInc-FastReports"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T21:25:41.808287Z"}}