← Back

CVE-2024-32642

nvd nist
Published: Dec 3, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

Affected (3)

Products: Masacms: Masacms
1 product
Masacms
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Masacms
Before 7.2.8
From 7.3 to 7.3.13
From 7.4.0 to 7.4.6

References (2)

Timeline

No history available yet.