Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jmr-r7p6-f5wr

Опубликовано: 29 апр. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.4

Описание

ShowDoc unrestricted file upload vulnerability

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution. This issue affects ShowDoc: before 2.8.7.

Пакеты

Наименование

showdoc/showdoc

composer
Затронутые версииВерсия исправления

< 2.8.7

2.8.7

EPSS

Процентиль: 73%
0.00763
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
9 месяцев назад

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

EPSS

Процентиль: 73%
0.00763
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-434