Remote Code Execution Vulnerability in Masa CMS by Masa Systems
CVE-2024-32641
9.8CRITICAL
What is CVE-2024-32641?
Masa CMS is an open-source Enterprise Content Management platform that suffered from a vulnerability in the addParam function. This vulnerability allows an unauthenticated attacker to inject arbitrary code through user input in the criteria parameter. The exploited input is then processed by setDynamicContent, which creates a pathway for remote code execution via the m tag. Users are strongly advised to upgrade to Masa CMS versions 7.2.8, 7.3.13, or 7.4.6 to mitigate this risk.
Affected Version(s)
MasaCMS >= 7.4.0, < 7.4.6 < 7.4.0, 7.4.6
MasaCMS >= 7.3.0, < 7.3.13 < 7.3.0, 7.3.13
MasaCMS < 7.2.8 < 7.2.8
