Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg32-m8mr-6xvg

Опубликовано: 11 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.

EPSS

Процентиль: 68%
0.00583
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
nvd
около 2 месяцев назад

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter.

EPSS

Процентиль: 68%
0.00583
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-94