logo

Hackers Exploit Critical ShowDoc RCE Flaw in Ongoing Attacks

ID: 3b58da3f-aadf-51f0-a199-ecc9d5af0cff

STIX ID: report--3b58da3f-aadf-51f0-a199-ecc9d5af0cff

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers disclosed a critical unauthenticated RCE in ShowDoc (CNVD-2020-26585) stemming from an unrestricted file upload in versions prior to 2.8.7; PoC exploits show attackers can POST a specially crafted file (e.g., disguised PHP webshell) to the /index.php?s=/home/page/uploadImg endpoint and then execute arbitrary code by visiting the uploaded file. Recommended mitigations include immediate upgrade to 2.8.7+, restricting public access (VPN), deploying a WAF to block suspicious uploads, and actively monitoring server logs for unusual file extensions or PHP execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.