CVE-2024-32640: MasaCMS SQL Injection vulnerability
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the processAsyncObject method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32640?
CVE-2024-32640 is considered a critical vulnerability due to its potential for remote code execution through SQL injection.
How do I fix CVE-2024-32640?
To mitigate CVE-2024-32640, upgrade MASA CMS to versions 7.4.6, 7.3.13, or 7.2.8 or later.
What versions are affected by CVE-2024-32640?
CVE-2024-32640 affects MASA CMS versions prior to 7.4.6, 7.3.13, and 7.2.8.
What kind of attack can occur due to CVE-2024-32640?
CVE-2024-32640 allows for SQL injection attacks that may lead to remote code execution on vulnerable systems.
Is there a workaround for CVE-2024-32640 until I can upgrade?
There is no official workaround for CVE-2024-32640; upgrading to a patched version is the recommended solution.