{ "schema_version": "1.4.0", "id": "GHSA-6jmr-r7p6-f5wr", "modified": "2025-04-30T17:31:58Z", "published": "2025-04-29T21:31:55Z", "aliases": [ "CVE-2025-0520" ], "summary": "ShowDoc unrestricted file upload vulnerability", "details": "An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution. This issue affects ShowDoc: before 2.8.7.", "severity": [ { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L" } ], "affected": [ { "package": { "ecosystem": "Packagist", "name": "showdoc/showdoc" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "2.8.7" } ] } ] } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0520" }, { "type": "WEB", "url": "https://github.com/star7th/showdoc/pull/1059" }, { "type": "PACKAGE", "url": "https://github.com/star7th/showdoc" }, { "type": "WEB", "url": "https://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585" }, { "type": "WEB", "url": "https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585" } ], "database_specific": { "cwe_ids": [ "CWE-434" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2025-04-30T17:31:58Z", "nvd_published_at": "2025-04-29T20:15:25Z" } }