Critical severity9.8OSV Advisory· Published Aug 11, 2025· Updated Apr 15, 2026
CVE-2024-32640
CVE-2024-32640
Description
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the processAsyncObject method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.
Affected products
1Patches
3259fc6061d02280489e2d6c83d6319b8775bVulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
6- github.com/MasaCMS/MasaCMS/commit/259fc6061d022d5025a3289a3f8de9852ad9c91dnvd
- github.com/MasaCMS/MasaCMS/commit/280489e2d6c8daf5022fdb0225235462dd9d4534nvd
- github.com/MasaCMS/MasaCMS/commit/3d6319b8775bb6438bc822d845926990511f5075nvd
- github.com/MasaCMS/MasaCMS/security/advisories/GHSA-24rr-gwx3-jhqcnvd
- projectdiscovery.io/blog/hacking-apple-with-sql-injectionnvd
- www.seebug.org/vuldb/ssvid-99835nvd
News mentions
0No linked articles in our index yet.