Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poi…
cve CVE-2024-32642 1 source, 1 claim · Watch
NVD writes:
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6. the claim
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6. the claim
- Severity
- HIGH NVD
- CVSS
- 8.8 NVD
- Vendor
- MasaCMS NVD
- Product
- MasaCMS NVD
- CWE
- CWE-346, CWE-640 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2025-12-03 | first spoke of it: Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6. | NVD |
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.
What it is to other things
| affects | masacms/masacms NVD |
| made_by | masacms NVD |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | NVD | 8.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:Hreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | NVD | CWE-346, CWE-640receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | poc A public proof of concept exists, or exploitation is trivial. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | MasaCMSreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | NVD | HIGH From 7.0 to 8.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | high | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | partial The attacker gains limited control, or limited information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | MasaCMSreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MasaCMS",
"vendor": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
}
],
"id": "CVE-2024-32642",
"lastModified": "2026-09-26T21:10:00.130",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32642",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-03T16:50:28.932386Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-03T17:15:48.543",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"
},
{
"source": "security-advisories@github.com",
"tags": [
"Exploit",
"Vendor Advisory"
],
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-346"
},
{
"lang": "en",
"value": "CWE-640"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6. zetlyn/cve-nvd · 2025-12-03 | automatable no cvss 8.8 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H cwe CWE-346, CWE-640 exploitation poc product MasaCMS severity HIGH status Analyzed technical_impact partial vendor MasaCMS | source |