Critical ShowDoc RCE Vulnerability Active Exploited in the Wild
ID: 2979c558-4fb8-5676-a0c9-604dcd251006
STIX ID: report--2979c558-4fb8-5676-a0c9-604dcd251006
Feed Name: cybersecurityNews.com
ShowDoc installations prior to version 2.8.7 are actively being exploited via an unrestricted file upload RCE (CNVD-2020-26585) in the /index.php?s=/home/page/uploadImg endpoint; attackers can bypass extension checks by manipulating filenames, upload PHP webshells with a single POST request, and execute arbitrary code. Administrators are urged to patch to 2.8.7+, restrict public access to documentation servers, enable WAF inspection, and review web server logs for suspicious upload requests.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
