CVE-2024-32640

A critical SQL injection vulnerability has been identified in multiple MASA CMS products, receiving the highest possible severity score.

Executive summary

A critical SQL injection vulnerability has been identified in multiple MASA CMS products, receiving the highest possible severity score. This flaw allows an unauthenticated attacker to execute arbitrary commands on the underlying database, potentially leading to a complete compromise of the system, including data theft, modification, and service disruption. Organizations using affected versions