CVE Database
/

CVE-2024-58284

Back to search

CVE-2024-58284

Published: Dec 10, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.

VendorProductVersions

PopojiCMS

PopojiCMS

affected
2.0.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now