github.com
https://github.com/thedigicraft/Atom.CMS/issues/263 CVE-2022-28032
CRITICALNuclei
Atom CMS v2.0 - SQL Injection
Record summary
CVE-2022-28032 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALAtom CMS v2.0 - SQL InjectionCVSS 9.8
AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Fixed in version Atom CMS v2.1
WeaknessesCWE-89
Authorstheamanrawat
Template tagstime-based-sqlicvecve2022sqliatomcmsthedigitalcraftvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thedigitalcraft:atomcms:2.0:*:*:*:*:*:*:*
https://github.com/thedigicraft/Atom.CMS/issues/263 https://nvd.nist.gov/vuln/detail/CVE-2022-28032 https://github.com/ARPSyndicate/cvemon https://github.com/bornrootcom/fictional-memory
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28032