Back to search
CVE-2024-58284
Published: Dec 10, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.
| Vendor | Product | Versions |
|---|---|---|
PopojiCMS | PopojiCMS | affected 2.0.1 |
Weaknesses (CWE)
References
ExploitDB-52022
exploit
Official Vendor Homepage
vendor-advisory
product
Product Archive
product
Project Repository
product
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now