CVE-2024-32642
PoC —CVSS 3.1
8.8 high
EPSS
<1%p10
Published
()
Modified
Description
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.
- Vendors
- masacms
- Products
- masacms
- Weakness
- CWE-346, CWE-640
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.