CVE-2024-32640

CRITICAL EXPLOITED NUCLEI

MASA CMS <7.4.5-7.2.7 - SQL Injection

Title source: llm

Description

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.

Exploits (4)

nomisec WORKING POC 77 stars
by Stuub · infoleak
https://github.com/Stuub/CVE-2024-32640-SQLI-MuraCMS
nomisec WORKING POC 1 stars
by 0xYumeko · infoleak
https://github.com/0xYumeko/CVE-2024-32640-SQLI-MuraCMS
nomisec WORKING POC 1 stars
by pizza-power · poc
https://github.com/pizza-power/CVE-2024-32640
nomisec WORKING POC
by sammings · infoleak
https://github.com/sammings/CVE-2024-32640

Nuclei Templates (1)

Mura/Masa CMS - SQL Injection
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan: Generator: Masa CMS || generator: masa cms

Scores

CVSS v3 9.8
EPSS 0.9372
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2024-05-16

Classification

CWE
CWE-89
Status draft

Timeline

Published Aug 11, 2025
Tracked Since Feb 18, 2026