External risk intelligence

Masa CMS Remote Code Execution via addParam Function

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2024-32641

Masa CMS is an enterprise content management platform. By design, such platforms are typically deployed as internet-facing web applications to serve public or authenticated user content, making the underlying application interface commonly reachable from the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Masa CMS platform, which could allow unauthenticated attackers to execute arbitrary code remotely. This issue impacts the core functionality of content management systems, potentially affecting the integrity and availability of digital information. The primary concern is to confirm if our organization utilizes this specific platform and, if so, to understand the extent of its exposure.

  • Unauthenticated remote code execution in content management.
  • Critical impact on platform integrity and data availability.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending specially crafted input to the `criteria` parameter within the `addParam` function. If this input is then processed by `setDynamicContent` and includes an "m tag," it could allow the attacker to execute arbitrary code on the server.

  • Entry condition: Unauthenticated network access.
  • Trigger point: Sending crafted input to `addParam`.
  • Resulting risk: Arbitrary code execution on the server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Masa CMS could allow an unauthenticated attacker to execute arbitrary code when they can provide input to the `criteria` parameter within the `addParam` function. This arbitrary code execution could impact the integrity and availability of the content management system.

  • System code execution.
  • Untrusted input via `criteria` parameter.
  • Compromised system integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical remote code execution vulnerability in Masa CMS affects systems that deploy it as an enterprise content management platform. Application owners or platform teams responsible for Masa CMS instances should initiate an inventory of all deployments to confirm exposure and business criticality. Following this, coordination with security and vendor management teams will be necessary to plan and execute remediation efforts based on risk.

  • Application owners must own the resolution.
  • Verify internet-facing Masa CMS instances.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Masa CMS and what is it used for?

Masa CMS is an open-source Enterprise Content Management (ECM) platform. Organizations use it to create, manage, and publish digital content on the web. It functions as the central system for maintaining websites, allowing teams to handle complex media and information structures for internal or public audiences.

How does CVE-2024-32641 trigger code execution?

This vulnerability is classified as CWE-94, or Improper Control of Generation of Code. It occurs when the software takes user-supplied input from the 'criteria' parameter and processes it through the 'setDynamicContent' function. If an attacker submits a specific 'm tag' within that input, the system incorrectly interprets it as executable code rather than plain content.

Do I need to be logged in to trigger this vulnerability?

No. This vulnerability does not require authentication. An attacker can attempt to trigger the issue remotely without needing a user account or special permissions. It is only triggered when specifically crafted data is sent to the 'addParam' function; simply visiting the site or accessing non-dynamic pages does not activate the bug.

Is my Masa CMS instance at risk?

Halo Surface Signal notes that Masa CMS is typically deployed as an internet-facing web application. Because it is designed to serve content to users, these instances are often reachable from the public internet. If your deployment is exposed to the network and runs an affected version, it is likely reachable by attackers.

When should I update my software to fix this?

You should prioritize updating as soon as possible. Check your current version and move to 7.2.8, 7.3.13, or 7.4.6, depending on your branch. The first step is to inventory all running instances to identify those on older, vulnerable versions. Once identified, coordinate with your team to apply the vendor's patch to restore system integrity.

References