PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can lo…
High CVSS 7.2
Summary
PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/PopojiCMS/PopojiCMS Product
- https://github.com/PopojiCMS/PopojiCMS/archive/refs/tags/v2.0.1.zip Release Notes
- https://www.exploit-db.com/exploits/52022 Exploit
- https://www.popojicms.org/ Product
- https://www.vulncheck.com/advisories/popojicms-remote-command-execution-via-authenticated-metadata-settings Third Party Advisory
- https://github.com/PopojiCMS/PopojiCMS/archive/refs/tags/v2.0.1.zip Release Notes
Timeline
- nvd_ingest NVD