---
id: CVE-2024-58284
title: >-
  PopojiCMS 2.0.1 contains an authenticated remote command execution
  vulnerability that allows administrative users to inject malicious PHP code
  through the metadata settings endpoint
summary: >-
  PopojiCMS 2.0.1 contains an authenticated remote command execution
  vulnerability that allows administrative users to inject malicious PHP code
  through the metadata settings endpoint. Attackers can log in and modify the
  meta content to cr…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: popojicms
product: popojicms
affected:
  - popojicms = 2.0.1
published: '2025-12-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58284'
references:
  - url: 'https://github.com/PopojiCMS/PopojiCMS'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/PopojiCMS/PopojiCMS/archive/refs/tags/v2.0.1.zip'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52022'
    label: disclosure@vulncheck.com
  - url: 'https://www.popojicms.org/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/popojicms-remote-command-execution-via-authenticated-metadata-settings
    label: disclosure@vulncheck.com
  - url: 'https://github.com/PopojiCMS/PopojiCMS/archive/refs/tags/v2.0.1.zip'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.01102
epssPercentile: 0.6435
ingestedAt: '2026-09-26T21:38:01.499Z'
---

## Overview

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.

## Affected

- `popojicms = 2.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
