CVE-2025-0520

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Nov 2025, 23:15

Type Values Removed Values Added
References
  • () https://www.vulncheck.com/advisories/showdoc-unauthenticated-file-upload-rceĀ -

02 May 2025, 13:53

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 20:15

Updated : 2025-11-04 23:15


NVD link : CVE-2025-0520

Mitre link : CVE-2025-0520

CVE.ORG link : CVE-2025-0520


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type