CVE-2024-58284EPSS p64.6%
CVE-2024-58284CVE-2024-58284
popojicms / popojicms
Description
PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.
Scoring
| CVSS | 7.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.10% probability of exploitation · percentile 64.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-26 |