Vulnerability record · CVE-2022-25487 · published 15 March 2022
CVE-2022-25487: Atom CMS unrestricted file upload in admin/uploads.php leads to RCE
Thedigitalcraft · Atomcms
Atom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious file that is then executed. The flaw is classified as CWE-434 and carries a critical CVSS 3.1 score of 9.8. Public exploit references exist, so the risk to exposed installations is significant.
Description
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with unauthenticated network reachability, public exploit references, and a high EPSS score make this a critical risk for any exposed Atom CMS v2.0 instance.
What it is
Atom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious file that is then executed. The flaw is classified as CWE-434 and carries a critical CVSS 3.1 score of 9.8. Public exploit references exist, so the risk to exposed installations is significant.
Impact
An attacker can upload and execute arbitrary code on the server, gaining full control of the web application and potentially the underlying host. This can lead to data theft, defacement, or use of the server as a foothold for further attacks.
Attack surface
The vulnerability is reached over the network via the /admin/uploads.php endpoint. The CVSS vector indicates no privileges or authentication are required (PR:N) and no user interaction is needed (UI:N), meaning the upload path is directly accessible to an unauthenticated attacker.
Exploitation
CVE-2022-25487 is not listed in CISA KEV, but public exploit code is referenced in Packet Storm and the vendor's GitHub issue tracker. EPSS gives a 30-day exploitation probability of roughly 0.54 (98.9th percentile), indicating high likelihood of active exploitation.
What to do
- Apply the vendor fix or upgrade Atom CMS to a version that restricts file uploads in /admin/uploads.php; if no patch is available, treat the endpoint as untrusted.
- Restrict access to /admin/uploads.php by IP allowlist or require authentication at the web server or reverse proxy layer.
- Enforce server-side file type, extension, and content validation on all uploads, and store uploaded files outside the web root with execution disabled.
- Deploy a WAF rule to block uploads of executable file types (e.g., .php, .phtml, .phar) to the admin upload path.
- Monitor and alert on new files written under the web root, especially in upload directories, and remove any unexpected executable files.
Detection
- Review web server and application logs for POST requests to /admin/uploads.php, particularly from unauthenticated or unexpected source IPs.
- Monitor file system changes in upload directories for newly created executable files (.php, .phtml, .phar, .jsp, .asp).
- Alert on outbound connections or child processes spawned by the web server user that are inconsistent with normal application behavior.
- Search for known exploit payload filenames or patterns associated with the public Packet Storm and GitHub issue references.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166532/Atom-CMS-1.0.2-Shell-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/thedigicraft/Atom.CMS/issues/256 | ExploitIssue TrackingThird Party Advisory |
| http://packetstormsecurity.com/files/166532/Atom-CMS-1.0.2-Shell-Upload.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/thedigicraft/Atom.CMS/issues/256 | ExploitIssue TrackingThird Party Advisory |
Track CVE-2022-25487 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.