Atom CMS
cpe:2.3:a:thedigitalcraft:atomcms:*:*:*:*:*:*:*
- 2.0
A SQL injection vulnerability has been identified in Atom CMS version 2.0. This issue allows remote attackers to execute time-based blind SQL injection attacks by injecting malicious SQL code into the 'id' parameter of the admin index page. The vulnerability arises from improper validation of parameters, enabling unauthorized manipulation of database queries.
Exploitation of this vulnerability allows for unauthenticated SQL injection, where attackers can execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.
To reproduce this vulnerability, send a POST request to the admin index page with a crafted 'id' parameter that includes malicious SQL code. The injected SQL code can be designed to, for example, use the 'sleep' function to create a time-based blind SQL injection effect, demonstrating the vulnerability.
Users are advised to update to Atom CMS version 2.1, which includes security patches for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.