← Back to browse · API

CVE-2024-32640

Severity
CRITICAL
CVSS
9.8
EPSS
0.70159
Risk score
63.76
CISA KEV
No
PoC
No
Published
2025-08-11
Modified
2025-12-03
First seen
2026-08-07
Aliases
EUVD-2024-30442
Products
MasaCMS:MasaCMS 7.3.0, < 7.3.12, MasaCMS:MasaCMS 7.4.0, < 7.4.5, MasaCMS:MasaCMS < 7.2.7
Sources
euvd EUVD-2024-30442

Description

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

References