« Volver al listado

CVE-2024-32642

Estado: AnalizadaAlta (8.8)—

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Host header poisoning en reset de contraseña (CWE-346) requiere interacción del usuario (UI:R) para abrir enlace malicioso. Logra acceso a cuenta (T1078.001) y manipulación de credenciales (T1098.001).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-32642",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-32642",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-03T16:50:28.932386Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "MasaCMS",
          "product": "MasaCMS",
          "versions": [
            {
              "status": "affected",
              "version": ">= 7.4.0, < 7.4.6"
            },
            {
              "status": "affected",
              "version": ">= 7.3.0, < 7.3.13"
            },
            {
              "status": "affected",
              "version": "< 7.2.8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-03T17:15:48.543",
  "references": [
    {
      "url": "https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        },
        {
          "lang": "en",
          "value": "CWE-640"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6."
    },
    {
      "lang": "es",
      "value": "Masa CMS es una plataforma de gestión de contenido empresarial de código abierto. Versiones anteriores a 7.2.8, 7.3.13 y 7.4.6 son vulnerables a envenenamiento de encabezado de host que permite la toma de control de cuentas a través de correo electrónico de restablecimiento de contraseña. Esta vulnerabilidad está corregida en 7.2.8, 7.3.13 y 7.4.6."
    }
  ],
  "lastModified": "2026-09-26T21:10:00.130",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82A74C33-3407-498A-9444-4A451E5968FE",
              "versionEndExcluding": "7.2.8"
            },
            {
              "criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45C4FA2D-DCEF-4991-B21D-C2BAC3A9DF5C",
              "versionEndExcluding": "7.3.13",
              "versionStartIncluding": "7.3"
            },
            {
              "criteria": "cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED61DA62-94D4-4081-923F-2674CFC7945A",
              "versionEndExcluding": "7.4.6",
              "versionStartIncluding": "7.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}