ShowDoc and VulnCheck Canary Honeypot: ShowDoc Vulnerability Patched in 2020 Now Used in Active Server Takeovers

ShowDoc and VulnCheck Canary Honeypot: ShowDoc Vulnerability Patched in 2020 Now Used in Active Server Takeovers

Hackers Revive Five-Year-Old ShowDoc Vulnerability in Global Attacks

A critical security flaw in ShowDoc, a PHP-based document collaboration tool popular in China, is being actively exploited by threat actors worldwide over five years after a patch was released. The vulnerability, tracked as CVE-2025-0520 (CVSS 9.4), allows unrestricted file uploads, enabling attackers to deploy malicious PHP files and gain remote code execution (RCE) on vulnerable servers.

Exploitation Details

  • The flaw stems from improper file-type validation, letting attackers upload web shells malicious scripts that grant unauthorized remote control.
  • Security firm VulnCheck detected active exploitation, including an attack on a U.S.-based "canary" honeypot running an outdated ShowDoc version.
  • While ShowDoc has a smaller user base than tools like SharePoint or Confluence, over 2,000 exposed instances remain online, primarily in China.

Why the Bug Persists

  • The vulnerability was fixed in ShowDoc 2.8.7 (October 2020), but many users failed to update, leaving systems exposed.
  • Threat actors are leveraging this as an N-day vulnerability an old, known flaw that remains unpatched in legacy systems.
  • The latest safe version is ShowDoc 3.8.1, but unpatched deployments continue to be targeted.

Expert Insights

  • Caitlin Condon (VulnCheck) noted that attackers are increasingly exploiting long-tail vulnerabilities in niche software to establish footholds for further attacks.
  • Will Baxter (Team Cymru) warned that even low-profile tools can serve as stepping stones for lateral movement or command-and-control operations, often evading internal security visibility.

The resurgence of this exploit underscores the risks of unpatched legacy software, particularly in tools with limited enterprise oversight. Organizations using ShowDoc are advised to verify their versions and apply updates immediately.

Source: https://hackread.com/showdoc-vulnerability-patch-2020-server-takeover/

VulnCheck cybersecurity rating report: https://www.rankiteo.com/company/vulncheck

"id": "VUL1776529417",
"linkid": "vulncheck",
"type": "Vulnerability",
"date": "10/2020",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Document Collaboration',
                        'location': 'Global (primarily China)',
                        'name': 'ShowDoc',
                        'type': 'Software'}],
 'attack_vector': 'Unrestricted file upload',
 'data_breach': {'file_types_exposed': 'PHP files (malicious web shells)'},
 'description': 'A critical security flaw in ShowDoc, a PHP-based document '
                'collaboration tool popular in China, is being actively '
                'exploited by threat actors worldwide over five years after a '
                'patch was released. The vulnerability, tracked as '
                'CVE-2025-0520 (CVSS 9.4), allows unrestricted file uploads, '
                'enabling attackers to deploy malicious PHP files and gain '
                'remote code execution (RCE) on vulnerable servers.',
 'impact': {'operational_impact': 'Unauthorized remote control of servers',
            'systems_affected': 'Over 2,000 exposed ShowDoc instances'},
 'lessons_learned': 'The resurgence of this exploit underscores the risks of '
                    'unpatched legacy software, particularly in tools with '
                    'limited enterprise oversight.',
 'post_incident_analysis': {'corrective_actions': 'Update to ShowDoc 3.8.1 or '
                                                  'later',
                            'root_causes': 'Improper file-type validation in '
                                           'ShowDoc, failure to apply patches'},
 'recommendations': 'Organizations using ShowDoc are advised to verify their '
                    'versions and apply updates immediately.',
 'references': [{'source': 'VulnCheck'}, {'source': 'Team Cymru'}],
 'response': {'remediation_measures': 'Apply ShowDoc update to version 3.8.1 '
                                      'or later',
              'third_party_assistance': 'VulnCheck'},
 'title': 'Hackers Revive Five-Year-Old ShowDoc Vulnerability in Global '
          'Attacks',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2025-0520 (CVSS 9.4)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.