---
cve: "CVE-2024-32640"
severity: "CRITICAL"
cvss: 9.8
epss: "76.6%"
vendor: "MasaCMS"
kev: false
exploited: false
published: "2025-08-11 21:15:26"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T09:22:52+02:00"
---

# CVE-2024-32640

> 9.8 CRITICAL · 🧪 PoC

## Beschreibung

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 11c02e748c5299f4b087fb9ce902e3cde4e13a92 (Commit)
- 7d9a5d775a656936054e16dd1ffc2208fd5af392 (Commit)

## Referenzen

- <https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-24rr-gwx3-jhqc>
- <https://github.com/MasaCMS/MasaCMS/commit/259fc6061d022d5025a3289a3f8de9852ad9c91d>
- <https://github.com/MasaCMS/MasaCMS/commit/280489e2d6c8daf5022fdb0225235462dd9d4534>
- <https://github.com/MasaCMS/MasaCMS/commit/3d6319b8775bb6438bc822d845926990511f5075>
- <https://github.com/Stuub/CVE-2024-32640-SQLI-MuraCMS>
- <https://projectdiscovery.io/blog/hacking-apple-with-sql-injection?ref=projectdiscovery-io-blog-newsletter>
- <https://www.seebug.org/vuldb/ssvid-99835>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-32640) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
