thedigicraft/Atom.CMS

thedigicraft/Atom.CMS

Releases1
Frequency
Last Release
Stars56
Atom.CMS

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

9.8 CRITICAL7.5 HIGH

AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php

9.8 CRITICAL7.5 HIGH

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

9.8 CRITICAL7.5 HIGH

AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php

9.8 CRITICAL7.5 HIGH

Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php

9.8 CRITICAL7.5 HIGH

AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php

9.8 CRITICAL7.5 HIGH

Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

9.8 CRITICAL7.5 HIGH

Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.

5.4 MEDIUM3.5 LOW

Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php.

9.8 CRITICAL7.5 HIGH

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.