CVE-2024-32643 Details
Description
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.
An authentication bypass vulnerability has been identified in Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6. When a page is restricted to specific user groups, it typically requires users to log in before accessing the content. However, by modifying the URL to include a '/tag/' declaration, the CMS will bypass these group restrictions and render the page content. This issue allows unauthorized users to access pages that should require authentication.
Users can update to Masa CMS versions 7.2.8, 7.3.13, or 7.4.6 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| masacms masacms | < 7.2.8 >= 7.3, < 7.3.13 >= 7.4.0, < 7.4.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | Initial Analysis | [email protected] |
| Dec 3, 2025 | New CVE Received | [email protected] |