ShowDoc unrestricted file upload vulnerability
Critical severity
GitHub Reviewed
Published
Apr 29, 2025
to the GitHub Advisory Database
•
Updated Apr 30, 2025
Description
Published by the National Vulnerability Database
Apr 29, 2025
Published to the GitHub Advisory Database
Apr 29, 2025
Reviewed
Apr 30, 2025
Last updated
Apr 30, 2025
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution. This issue affects ShowDoc: before 2.8.7.
References