---
id: CVE-2024-32642
title: Masa CMS is an open source Enterprise Content Management platform
summary: >-
  Masa CMS is an open source Enterprise Content Management platform. Prior to
  7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which
  allows account takeover via password reset email. This vulnerability is fixed
  in 7.2…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-346
  - CWE-640
vendor: masacms
product: masacms
affected:
  - masacms < 7.2.8
  - 'masacms >= 7.3, < 7.3.13'
  - 'masacms >= 7.4.0, < 7.4.6'
patched:
  - masacms 7.4.6
published: '2025-12-03'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-32642'
references:
  - url: >-
      https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960
    label: security-advisories@github.com
  - url: 'https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.002
epssPercentile: 0.08894
ingestedAt: '2026-09-26T21:38:01.493Z'
---

## Overview

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.

## Affected

- `masacms < 7.2.8`
- `masacms >= 7.3, < 7.3.13`
- `masacms >= 7.4.0, < 7.4.6`

## Remediation

Upgrade past the affected range:

- `masacms 7.4.6`
