← Back to browse · API

CVE-2024-32641

Severity
CRITICAL
CVSS
9.8
EPSS
0.12297
Risk score
43.5
CISA KEV
No
PoC
No
Published
2025-12-03
Modified
2025-12-03
First seen
2026-08-07
Aliases
EUVD-2024-30443
Products
MasaCMS:MasaCMS 7.3.0, < 7.3.13, MasaCMS:MasaCMS 7.4.0, < 7.4.6, MasaCMS:MasaCMS < 7.2.8
Sources
euvd EUVD-2024-30443

Description

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6.

References