PT-2025-52712 · Atomcms · Atomcms

Hubert Wojciechowski

·

Published

2025-12-22

·

Updated

2026-01-02

·

CVE-2023-53975

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Atom CMS version 2.0
Description Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the id parameter of the admin index page to execute time-based blind SQL injection attacks. The vulnerability allows for remote database manipulation via the unvalidated id parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-53975

Affected Products

Atomcms