Record summary

CVE-2022-28033 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALAtom.CMS 2.0 - SQL InjectionCVSS 9.8

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php which allows an attacker to execute arbitrary SQL commands.

Impact

Successful exploitation could lead to unauthorized access, data leakage, and potential data manipulation.

Remediation

Apply the latest security patches provided by the vendor to mitigate the SQL Injection vulnerability in Atom.CMS 2.0.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2022atomcmssqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thedigitalcraft:atomcms:2.0:*:*:*:*:*:*:*
Shodan: html:"atomcms"

Source: ProjectDiscovery

References

2