Skip to content

PRP: Request SQLi in Mura/Masa CMS (CVE-2024-32640) #497

@W0ngL1

Description

@W0ngL1

Hi there.

I would like to start implementing a plugin to detect SQLi in Mura/Masa CMS (CVE-2024-32640). This vulnerability was published on May 2024, and Apple has been hacked cause this vulnerability, https://blog.projectdiscovery.io/hacking-apple-with-sql-injection/.

References:
https://nvd.nist.gov/vuln/detail/CVE-2024-32640
https://blog.projectdiscovery.io/hacking-apple-with-sql-injection/

Description:
Mura CMS and Masa CMS are content management systems designed to facilitate the creation, management, and deployment of digital content for websites and web applications. Both CMS platforms offer robust features tailored to different needs, though they share some common capabilities.

Affected Versions:
Masa CMS < 7.4.6/7.3.13/7.2.8

Thanks.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions