Record summary

CVE-2022-24223 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBAtomCMS v2.0 - SQLiExploitDB exploitby Luca CuzzolinNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALAtom CMS v2.0 - SQL InjectionCVSS 9.8

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Fixed in version Atom CMS v2.1

WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022packetstormsqliatomcmsthedigitalcraftvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thedigitalcraft:atomcms:2.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3