Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c2r6-r382-m667

Опубликовано: 23 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 8.2

Описание

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

EPSS

Процентиль: 30%
0.0011
Низкий

9.3 Critical

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

EPSS

Процентиль: 30%
0.0011
Низкий

9.3 Critical

CVSS4

8.2 High

CVSS3

Дефекты

CWE-89