CVE-2025-0520
EPSS 2.0%ShowDoc unrestricted file upload vulnerability
發布日:2025/4/29修改日:2025/11/5
描述
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution. This issue affects ShowDoc: before 2.8.7.
受影響套件(1)
- Packagist/showdoc/showdocfrom 0, < 2.8.7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-0520
- PATCHhttps://github.com/star7th/showdoc
- WEBhttps://github.com/star7th/showdoc/pull/1059
- WEBhttps://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585
- WEBhttps://www.cnvd.org.cn/flaw/show/CNVD-2020-26585
- WEBhttps://www.vulncheck.com/advisories/showdoc-unauthenticated-file-upload-rce