Critical ShowDoc RCE Vulnerability Actively Exploited in the Wild
ID: 346156d9-5c70-57b7-a60b-df6f1ec14c5a
STIX ID: report--346156d9-5c70-57b7-a60b-df6f1ec14c5a
Feed Name: Cyber Press
Threat Score
Researchers warn of an actively exploited unauthenticated RCE (CNVD-2020-26585) in ShowDoc versions before 2.8.7 that permits attackers to upload PHP webshells via the /index.php?s=/home/page/uploadImg endpoint, enabling full remote code execution; administrators are urged to upgrade to 2.8.7+, restrict external access, deploy WAFs, and monitor logs for malicious uploads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
