CVE-2024-32641
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 12%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 %
CMS expuesto en red (AV:N/PR:N/UI:N), sin autenticación requerida. Entrada de usuario sin validar en parámetro 'criteria' evaluada directamente (CWE-94: Improper Control of Generation of Code), permitiendo ejecución arbitraria de código remoto.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-32641",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-32641",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-12-03T16:31:34.466457Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "MasaCMS",
"product": "MasaCMS",
"versions": [
{
"status": "affected",
"version": ">= 7.4.0, < 7.4.6"
},
{
"status": "affected",
"version": ">= 7.3.0, < 7.3.13"
},
{
"status": "affected",
"version": "< 7.2.8"
}
]
}
]
}
],
"published": "2025-12-03T17:15:48.220",
"references": [
{
"url": "https://github.com/MasaCMS/MasaCMS/commit/fb27f822fe426496af71205fa35208e58823fcf6",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-cj9g-v5mq-qrjm",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6."
},
{
"lang": "es",
"value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a Masa CMS 7.2.8, 7.3.13 y 7.4.6 son vulnerables a ejecución remota de código. La vulnerabilidad existe en la función addParam, que acepta la entrada del usuario a través del parámetro criteria. Esta entrada es posteriormente evaluada por setDynamicContent, permitiendo a un atacante no autenticado ejecutar código arbitrario a través de la etiqueta m. La vulnerabilidad está parcheada en las versiones 7.2.8, 7.3.13 y 7.4.6."
}
],
"lastModified": "2026-09-26T21:10:00.130",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
"versionEndExcluding": "7.2.8"
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
"versionEndExcluding": "7.3.13",
"versionStartIncluding": "7.3"
},
{
"criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
"versionEndExcluding": "7.4.6",
"versionStartIncluding": "7.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}