CVE-2024-58284 Details
Description
PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.
A remote command execution vulnerability has been identified in PopojiCMS version 2.0.1. This issue allows authenticated administrative users to inject malicious PHP code through the metadata settings endpoint. Once the code is injected, it can be used to create a web shell that executes arbitrary system commands via a GET parameter.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/PopojiCMS/PopojiCMS/archive/refs/tags/v2.0.1.zip | CISA-ADP | Release Notes |
| https://github.com/PopojiCMS/PopojiCMS | [email protected] | Product |
| https://github.com/PopojiCMS/PopojiCMS/archive/refs/tags/v2.0.1.zip | [email protected] | Release Notes |
| https://www.exploit-db.com/exploits/52022 | [email protected] | ExploitThird Party Advisory |
| https://www.popojicms.org/ | [email protected] | Product |
| https://www.vulncheck.com/advisories/popojicms-remote-command-execution-via-authenticated-metadata-settings | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| popojicms popojicms | 2.0.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 19, 2025 | Initial Analysis | [email protected] |
| Dec 11, 2025 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | New CVE Received | [email protected] |