Showdoc · Showdoc · CVE-2021-36440
**Name of the Vulnerable Software and Affected Versions**
ShowDoc version 2.9.5
**Description**
The issue allows remote attackers to execute arbitrary code via the `file url` parameter in the AdminUpdateController.class.php component. This enables attackers to upload files without restrictions, potentially leading to code execution.
**Recommendations**
For ShowDoc version 2.9.5, consider restricting access to the `file url` parameter in the AdminUpdateController.class.php component to minimize the risk of exploitation. As a temporary workaround, avoid using the `file url` parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.