CVE Vulnerabilities

CVE-2024-32642

Origin Validation Error

Published: Dec 03, 2025 | Modified: Dec 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Masacms Masacms * 7.2.8 (excluding)
Masacms Masacms 7.3 (including) 7.3.13 (excluding)
Masacms Masacms 7.4.0 (including) 7.4.6 (excluding)

References