SQL Injection Vulnerability in MASA CMS by MASA Technologies
CVE-2024-32640
9.8CRITICAL
What is CVE-2024-32640?
A SQL injection vulnerability exists in the MASA CMS platform in the processAsyncObject
method. This flaw can allow an attacker to execute arbitrary SQL commands, which may lead to unauthorized access and the potential for remote code execution. Users are encouraged to upgrade to versions 7.4.6, 7.3.13, or 7.2.8 for enhanced security measures.
Affected Version(s)
MasaCMS >= 7.4.0, < 7.4.6 < 7.4.0, 7.4.6
MasaCMS >= 7.3.0, < 7.3.13 < 7.3.0, 7.3.13
MasaCMS < 7.2.8 < 7.2.8