CVE-2024-32640
CRITICAL EXPLOITED NUCLEIMASA CMS <7.4.5-7.2.7 - SQL Injection
Title source: llmDescription
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.
Exploits (4)
nomisec
WORKING POC
77 stars
by Stuub · infoleak
https://github.com/Stuub/CVE-2024-32640-SQLI-MuraCMS
nomisec
WORKING POC
1 stars
by 0xYumeko · infoleak
https://github.com/0xYumeko/CVE-2024-32640-SQLI-MuraCMS
Nuclei Templates (1)
Mura/Masa CMS - SQL Injection
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan:
Generator: Masa CMS || generator: masa cms
References (7)
Scores
CVSS v3
9.8
EPSS
0.9372
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2024-05-16
Classification
CWE
CWE-89
Status
draft
Timeline
Published
Aug 11, 2025
Tracked Since
Feb 18, 2026