Back to search
CVE-2025-0520
Published: Apr 29, 2025
Modified: Nov 19, 2025
PUBLISHED
Description
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
| Vendor | Product | Versions |
|---|---|---|
ShowDoc | ShowDoc | affected 0 - < 2.8.7 |
Weaknesses (CWE)
References
https://github.com/star7th/showdoc/pull/1059
patch
issue-tracking
https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585
third-party-advisory
https://www.vulncheck.com/advisories/showdoc-unauthenticated-file-upload-rce
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now