PT-2025-18203 · Showdoc · Showdoc

Plzmyy

·

Published

2025-04-29

·

Updated

2025-05-02

·

CVE-2025-0520

CVSS v4.0

9.4

Critical

AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions ShowDoc versions prior to 2.8.7
Description An unrestricted file upload vulnerability in ShowDoc is caused by improper validation of file extension, allowing execution of arbitrary PHP and leading to remote code execution.
Recommendations For versions prior to 2.8.7, update to version 2.8.7 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to only necessary and validated extensions until a patch is applied. Restrict access to sensitive areas of the system to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-0520
GHSA-6JMR-R7P6-F5WR

Affected Products

Showdoc