← Vulnerability feed

Vulnerability record · CVE-2022-25487 · published 15 March 2022

CVE-2022-25487: Atom CMS unrestricted file upload in admin/uploads.php leads to RCE

Thedigitalcraft · Atomcms

Atom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious file that is then executed. The flaw is classified as CWE-434 and carries a critical CVSS 3.1 score of 9.8. Public exploit references exist, so the risk to exposed installations is significant.

9.8 CVSS 3.1 Critical EPSS 54% · top 1.0% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with unauthenticated network reachability, public exploit references, and a high EPSS score make this a critical risk for any exposed Atom CMS v2.0 instance.

What it is

Atom CMS v2.0 contains an unrestricted file upload vulnerability reachable through /admin/uploads.php, allowing an attacker to upload a malicious file that is then executed. The flaw is classified as CWE-434 and carries a critical CVSS 3.1 score of 9.8. Public exploit references exist, so the risk to exposed installations is significant.

Impact

An attacker can upload and execute arbitrary code on the server, gaining full control of the web application and potentially the underlying host. This can lead to data theft, defacement, or use of the server as a foothold for further attacks.

Attack surface

The vulnerability is reached over the network via the /admin/uploads.php endpoint. The CVSS vector indicates no privileges or authentication are required (PR:N) and no user interaction is needed (UI:N), meaning the upload path is directly accessible to an unauthenticated attacker.

Exploitation

CVE-2022-25487 is not listed in CISA KEV, but public exploit code is referenced in Packet Storm and the vendor's GitHub issue tracker. EPSS gives a 30-day exploitation probability of roughly 0.54 (98.9th percentile), indicating high likelihood of active exploitation.

What to do

  • Apply the vendor fix or upgrade Atom CMS to a version that restricts file uploads in /admin/uploads.php; if no patch is available, treat the endpoint as untrusted.
  • Restrict access to /admin/uploads.php by IP allowlist or require authentication at the web server or reverse proxy layer.
  • Enforce server-side file type, extension, and content validation on all uploads, and store uploaded files outside the web root with execution disabled.
  • Deploy a WAF rule to block uploads of executable file types (e.g., .php, .phtml, .phar) to the admin upload path.
  • Monitor and alert on new files written under the web root, especially in upload directories, and remove any unexpected executable files.

Detection

  • Review web server and application logs for POST requests to /admin/uploads.php, particularly from unauthenticated or unexpected source IPs.
  • Monitor file system changes in upload directories for newly created executable files (.php, .phtml, .phar, .jsp, .asp).
  • Alert on outbound connections or child processes spawned by the web server user that are inconsistent with normal application behavior.
  • Search for known exploit payload filenames or patterns associated with the public Packet Storm and GitHub issue references.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/166532/Atom-CMS-1.0.2-Shell-Upload.html ExploitThird Party AdvisoryVDB Entry
https://github.com/thedigicraft/Atom.CMS/issues/256 ExploitIssue TrackingThird Party Advisory
http://packetstormsecurity.com/files/166532/Atom-CMS-1.0.2-Shell-Upload.html ExploitThird Party AdvisoryVDB Entry
https://github.com/thedigicraft/Atom.CMS/issues/256 ExploitIssue TrackingThird Party Advisory

Track CVE-2022-25487 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28032Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.phpEPSS 5.9%9.8CVE-2022-28033Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.phpEPSS 5.3%9.8CVE-2022-28034Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.phpEPSS 1.4%9.8CVE-2022-28035Thedigitalcraft atomcms sql injection vulnerabilityAtom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.phpEPSS 1.4%9.8CVE-2022-28036Thedigitalcraft atomcms sql injection vulnerabilityAtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.phpEPSS 1.4%9.8CVE-2022-25488Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.EPSS 7.1%9.8CVE-2022-24223AtomCMS admin login SQL injectionAtomCMS v2.0 contains a SQL injection vulnerability reached through /admin/login.php. The flaw is rated critical (CVSS 9.8) and public exploit refere…EPSS 62%analysed9.3CVE-2023-53975Thedigitalcraft atomcms sql injection vulnerabilityAtom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2022-25487), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.