packetstormsecurity.com
http://packetstormsecurity.com/files/165922/Atom-CMS-2.0-SQL-Injection.html CVE-2022-24223
CRITICALNuclei
AtomCMS v2.0 - SQLi
Record summary
CVE-2022-24223 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBAtomCMS v2.0 - SQLiExploitDB exploitby Luca CuzzolinNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALAtom CMS v2.0 - SQL InjectionCVSS 9.8
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Fixed in version Atom CMS v2.1
WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022packetstormsqliatomcmsthedigitalcraftvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thedigitalcraft:atomcms:2.0:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/165922/Atom-CMS-2.0-SQL-Injection.html https://github.com/thedigicraft/Atom.CMS/issues/255 https://nvd.nist.gov/vuln/detail/CVE-2022-24223 https://github.com/ARPSyndicate/cvemon https://github.com/Enes4xd/Enes4xd
Source: ProjectDiscovery
References
3github.com
https://github.com/thedigicraft/Atom.CMS/issues/255 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-24223