CVE-2024-32642

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*
cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*
cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-03 17:15

Updated : 2025-12-05 15:36


NVD link : CVE-2024-32642

Mitre link : CVE-2024-32642

CVE.ORG link : CVE-2024-32642


JSON object : View

Products Affected

masacms

  • masacms
CWE
CWE-346

Origin Validation Error

CWE-640

Weak Password Recovery Mechanism for Forgotten Password