CVE-2022-24223Active Exploitation(thedigitalcraft / atomcms)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch thedigitalcraft atomcms systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • atomcms

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
atomcms

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-05: 1PoC Mentioned / Linked · 2026-02-05: 1Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-05: 102-05
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2022-24223 : ATOMCMS v2.0 AUTHENTICATION BYPASS VIA SQL INJECTION 🚨 A critical SQL injection vulnerability has been identified in AtomCMS v2.0, allowing unauthenticated attackers to bypass the admin login entirely and gain full administrative control of affected websites. Risk Severity: Critical — CVSS 9.8 Active exploitation observed, public proof-of-concept available Impact: - Complete administrative account takeover - Full read/write access to all database content - Theft of user credentials, authentication tokens, and configuration secrets - Website defacement, malware injection, SEO spam, and persistent backdoors - Potential pivot to remote code execution depending on database privileges Root Cause: - CWE-89 (SQL Injection). The `/admin/login.php` endpoint directly concatenates user-supplied credentials into SQL queries without parameterization or input sanitization, collapsing the authentication boundary. Attackers can: - Send unauthenticated POST requests to `/admin/login.php` - Inject SQL logic into `username` or `password` fields - Bypass authentication using `OR 1=1`, UNION-based, blind, or error-based injection - Extract or modify all database records - Implant malicious content or web shells for persistent access Are You Affected? - Vulnerable: AtomCMS v2.0 (all patch levels) - Exposure: Any internet-facing AtomCMS instance with an accessible admin login - Threat Status: Confirmed active exploitation in the wild Fix Status: Vendor fix not publicly documented — treat all v2.0 deployments as vulnerable Immediate Action Required: - Patch: Contact AtomCMS vendor immediately for emergency remediation guidance - Restrict: Lock down `/admin/login.php` behind VPN or IP allowlists - Shield: Deploy WAF rules blocking SQL meta-characters and injection patterns in login requests - Throttle: Apply strict rate limiting on admin authentication attempts Detection & Monitoring: - Web logs: Hunt for POST requests to `/admin/login.php` containing `UNION`, `SELECT`, `OR 1=`, `SLEEP()`, `BENCHMARK()` - Database logs: Alert on unexpected queries against admin tables - Auth telemetry: Watch for admin logins from unknown IPs or abnormal timing - Network layer: Detect SQLMap user agents and mass scanning behavior Incident Response: If compromise is suspected: - Immediately rotate all admin credentials and invalidate active sessions - Audit database changes and content integrity - Scan for web shells, rogue admin users, and injected scripts - Assume full CMS compromise and assess server-level impact Why This Matters: This is a total authentication failure. The login mechanism itself is the exploit. With active exploitation underway, unpatched AtomCMS v2.0 instances should be treated as already at risk. Act now. 🛡️ #ostorlabCVE

    Post summary

    The post highlights a critical SQL injection in AtomCMS v2.0 that is actively exploited in the wild, with a public PoC available, and provides urgent mitigation guidance.

    0001085
    582 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appthedigitalcraftatomcms2.0--

Explore more