Description
Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Hubert Wojciechowski
References
www.exploit-db.com/exploits/51086 (ExploitDB-51086)
github.com/thedigicraft/Atom.CMS (Atom CMS GitHub Repository)
www.vulncheck.com/...ated-sql-injection-via-admin-index-page (VulnCheck Advisory: Atom CMS 2.0 Unauthenticated SQL Injection via Admin Index Page)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.