Vulnerability record · CVE-2022-24223 · published 1 February 2022
CVE-2022-24223: AtomCMS admin login SQL injection
Thedigitalcraft · Atomcms
AtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit references exist, so any exposed instance is a realistic target.
Description
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and a very high EPSS score make this an urgent exposure for any internet-facing AtomCMS v2.0 instance.
What it is
AtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit references exist, so any exposed instance is a realistic target.
Impact
An unauthenticated attacker can inject SQL through the login endpoint, potentially reading or modifying database contents and bypassing authentication. Given the CVSS scope, full compromise of confidentiality, integrity and availability is possible.
Attack surface
Reachable over the network via HTTP requests to /admin/login.php; the CVSS vector shows no privileges and no user interaction required. No authentication is needed to reach the vulnerable endpoint.
Exploitation
Not listed in CISA KEV, but EPSS is 0.61965 (99th percentile) and both references are tagged Exploit, indicating public exploit material is available.
What to do
- Apply the vendor fix or upgrade AtomCMS past v2.0 if a patched release exists; verify against the project's issue tracker.
- If no patch is available, take the admin login page off the public internet or place it behind a VPN or IP allowlist.
- Use parameterized queries or prepared statements for all login form database access.
- Deploy a WAF rule targeting SQL injection patterns on /admin/login.php as a stopgap.
- Rotate database credentials and review database logs for tampering if exposure is suspected.
Detection
- Monitor web logs for SQL metacharacters (quotes, UNION, OR 1=1, comment sequences) in POST bodies to /admin/login.php.
- Alert on repeated failed login attempts from a single source against the admin login endpoint.
- Review database query logs for anomalous or malformed statements originating from the web application.
- Check for unexpected changes to admin user records or authentication bypass events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165922/Atom-CMS-2.0-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/thedigicraft/Atom.CMS/issues/255 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/165922/Atom-CMS-2.0-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/thedigicraft/Atom.CMS/issues/255 | ExploitThird Party Advisory |
Track CVE-2022-24223 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.