An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
History

Tue, 29 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 20:00:00 +0000

Type Values Removed Values Added
References

Tue, 29 Apr 2025 19:45:00 +0000

Type Values Removed Values Added
Description An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
Title ShowDoc Unauthenticated File Upload Remote Code Execution
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-04-29T19:35:37.829Z

Updated: 2025-04-29T20:41:34.177Z

Reserved: 2025-01-16T17:23:23.838Z

Link: CVE-2025-0520

cve-icon Vulnrichment

Updated: 2025-04-29T20:41:25.436Z

cve-icon NVD

Status : Received

Published: 2025-04-29T20:15:25.230

Modified: 2025-04-29T20:15:25.230

Link: CVE-2025-0520

cve-icon Redhat

No data.