CVE-2020-15865

CRITICAL

Stimulsoft Reports 2013.1.1600.0 - Remote Code Execution via Base-64 Encoded C# Scripts in Report XML

Title source: llm
STIX 2.1

Description

A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0512
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
stimulsoft/reports 2013.1.1600.0
Published Aug 18, 2020
Tracked Since Feb 18, 2026