ShowDoc 3.9.2 flaw lets username field become PHP code
QiAnXin published QVD-2026-61708: ShowDoc 3.9.2 has an unauthenticated RCE in SQLite-backed deployments. The registerByVerify route lets attackers write PHP code into Sqlite/showdoc.db.php under the web root. It is fixed in version 3.9.3.
- The flaw affects SQLite-backed ShowDoc deployments and is fixed in version 3.9.3
- The unauthenticated registerByVerify route writes PHP code into Sqlite/showdoc.db.php
- Eagle Map counts 20,491 related risk assets across 4,866 IP addresses in China
- Interim fixes: disable registration, deny /Sqlite/ in Nginx, move the DB file out of the web root
Read next
Security