CVE-2024-32640

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.
Configurations

No configuration.

History

03 Dec 2025, 16:15

Type Values Removed Values Added
Summary (en) MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.6, 7.3.13, and 7.2.8 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.6, 7.3.13, and 7.2.8 contain a fix for the issue. (en) MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.
References
  • {'url': 'https://github.com/MasaCMS/MasaCMS/releases/tag/7.2.8', 'source': '[email protected]'}
  • {'url': 'https://github.com/MasaCMS/MasaCMS/releases/tag/7.3.13', 'source': '[email protected]'}
  • {'url': 'https://github.com/MasaCMS/MasaCMS/releases/tag/7.4.6', 'source': '[email protected]'}
  • () https://github.com/MasaCMS/MasaCMS/commit/259fc6061d022d5025a3289a3f8de9852ad9c91d -
  • () https://github.com/MasaCMS/MasaCMS/commit/280489e2d6c8daf5022fdb0225235462dd9d4534 -
  • () https://github.com/MasaCMS/MasaCMS/commit/3d6319b8775bb6438bc822d845926990511f5075 -

Information

Published : 2025-08-11 21:15

Updated : 2025-12-03 16:15


NVD link : CVE-2024-32640

Mitre link : CVE-2024-32640

CVE.ORG link : CVE-2024-32640


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')