Description
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6.
INFO
Published Date :
2025-12-03T16:26:00.795Z
Last Modified :
2025-12-03T16:31:42.106Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2024-32641 vulnerability.
| Vendors | Products |
|---|---|
| Masacms |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-32641.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact