github.com
https://github.com/thedigicraft/Atom.CMS/issues/259 CVE-2022-28033
CRITICALNuclei
Atom.CMS 2.0 - SQL Injection
Record summary
CVE-2022-28033 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALAtom.CMS 2.0 - SQL InjectionCVSS 9.8
Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php which allows an attacker to execute arbitrary SQL commands.
Impact
Successful exploitation could lead to unauthorized access, data leakage, and potential data manipulation.
Remediation
Apply the latest security patches provided by the vendor to mitigate the SQL Injection vulnerability in Atom.CMS 2.0.
WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2022atomcmssqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thedigitalcraft:atomcms:2.0:*:*:*:*:*:*:*
Shodan: html:"atomcms"
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28033