← Vulnerability feed

Vulnerability record · CVE-2022-24223 · published 1 February 2022

CVE-2022-24223: AtomCMS admin login SQL injection

Thedigitalcraft · Atomcms

AtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit references exist, so any exposed instance is a realistic target.

9.8 CVSS 3.1 Critical EPSS 62% · top 0.8% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and a very high EPSS score make this an urgent exposure for any internet-facing AtomCMS v2.0 instance.

What it is

AtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit references exist, so any exposed instance is a realistic target.

Impact

An unauthenticated attacker can inject SQL through the login endpoint, potentially reading or modifying database contents and bypassing authentication. Given the CVSS scope, full compromise of confidentiality, integrity and availability is possible.

Attack surface

Reachable over the network via HTTP requests to /admin/login.php; the CVSS vector shows no privileges and no user interaction required. No authentication is needed to reach the vulnerable endpoint.

Exploitation

Not listed in CISA KEV, but EPSS is 0.61965 (99th percentile) and both references are tagged Exploit, indicating public exploit material is available.

What to do

  • Apply the vendor fix or upgrade AtomCMS past v2.0 if a patched release exists; verify against the project's issue tracker.
  • If no patch is available, take the admin login page off the public internet or place it behind a VPN or IP allowlist.
  • Use parameterized queries or prepared statements for all login form database access.
  • Deploy a WAF rule targeting SQL injection patterns on /admin/login.php as a stopgap.
  • Rotate database credentials and review database logs for tampering if exposure is suspected.

Detection

  • Monitor web logs for SQL metacharacters (quotes, UNION, OR 1=1, comment sequences) in POST bodies to /admin/login.php.
  • Alert on repeated failed login attempts from a single source against the admin login endpoint.
  • Review database query logs for anomalous or malformed statements originating from the web application.
  • Check for unexpected changes to admin user records or authentication bypass events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28032Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.phpEPSS 5.9%9.8CVE-2022-28033Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.phpEPSS 5.3%9.8CVE-2022-28034Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.phpEPSS 1.4%9.8CVE-2022-28035Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.phpEPSS 1.4%9.8CVE-2022-28036Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.phpEPSS 1.4%9.8CVE-2022-25487Atom CMS unrestricted file upload in admin/uploads.php leads to RCEAtom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious fil…EPSS 54%analysed9.8CVE-2022-25488Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.EPSS 7.1%9.3CVE-2023-53975Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2022-24223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.