S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-24223 Scanner

CVE-2022-24223 scanner - SQL Injection vulnerability in Atom CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-24223
9.8
CVSS

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Atom CMS is a content management system designed to help users easily create and manage their websites. It is aimed at providing a simple yet powerful platform for web development, especially for users with limited coding knowledge. The software allows for easy content updates, user management, and customization of web pages through a user-friendly interface. It is particularly popular among small businesses and individual bloggers who require a straightforward solution for their web presence. Version 2.0 of Atom CMS has been identified to contain a critical SQL Injection vulnerability, affecting the security of websites using this version.

The SQL Injection vulnerability in Atom CMS version 2.0 allows attackers to execute arbitrary SQL commands through the admin login page. This vulnerability exposes the system to unauthorized access, where attackers can manipulate the database, access sensitive information, or potentially take control of the affected web application. The issue is particularly severe because it requires no user authentication to exploit, making it accessible to any attacker who can send crafted requests to the vulnerable login page.

The vulnerability is specifically found in the /admin/login.php file, where user input from the email field is improperly sanitized before being used in SQL queries. This allows an attacker to inject malicious SQL code by manipulating the input fields on the login form. By exploiting this flaw, attackers can bypass authentication, retrieve data from the database, or even perform administrative actions without proper credentials. The vulnerability showcases the critical importance of input validation and sanitization in web applications.

Exploitation of this vulnerability could lead to severe consequences including unauthorized access to the CMS's administrative functions, exposure of sensitive data such as user credentials and personal information, and potential compromise of the entire web application. In the worst-case scenario, attackers could leverage this access to launch further attacks against the website's users or underlying server infrastructure.

By leveraging the S4E platform, users can detect and address vulnerabilities like the SQL Injection in Atom CMS v2.0, ensuring their digital assets are protected against cyber threats. Our platform offers comprehensive scanning capabilities that highlight security weaknesses and provide detailed recommendations for remediation. Joining S4E empowers website owners with the tools and knowledge needed to maintain a secure and trustworthy online presence.

 

References

Solution Advice
  1. Upgrade to Atom CMS version 2.1 or later, which contains the necessary patches to mitigate the SQL Injection vulnerability.
  2. Regularly update all software components to their latest versions to protect against known vulnerabilities.
  3. Implement robust input validation and sanitization routines to prevent SQL Injection attacks across the application.
  4. Conduct security audits and vulnerability assessments regularly to identify and remediate potential security issues before they can be exploited.
  5. Educate developers and administrators about secure coding practices and the importance of security in the development lifecycle.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.