Description

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6.

INFO

Published Date :

2025-12-03T16:26:00.795Z

Last Modified :

2025-12-03T16:31:42.106Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-32641 vulnerability.

Vendors Products
Masacms
  • Masacms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-32641.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact