CVE-2024-32640 is a critical SQL injection vulnerability in MASA CMS, also described in the provided content as affecting the related Masa/Mura CMS JSON API. The flaw is in the processAsyncObject method, specifically where user-controlled input from the contenthistid parameter is concatenated into SQL queries in the getObjects function without sufficient sanitization. The vulnerable endpoint is described as /_api/json/v1/default/?method=processAsyncObject. The content further states that exploitation can require forcing the vulnerable code path by supplying a previewID parameter and that quote escaping in Lucee CFML can be bypassed using a backslash escape sequence before a single quote. Successful exploitation allows attackers to perform arbitrary SQL queries against the backend database and, according to the provided material, can be escalated to remote code execution by extracting administrative credentials or tokens and then abusing the CMS plugin installation feature to upload malicious CFML code. The vendor description states that versions prior to 7.4.5, 7.3.12, and 7.2.7 are affected, while other provided supporting content references patched versions 7.4.6, 7.3.13, and 7.2.8; this version discrepancy is present in the source material.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/_api/json/v1/default/, particularly unauthenticated access to method=processAsyncObject. Apply WAF or reverse-proxy filtering to block suspicious SQL metacharacters and encoded backslash/single-quote sequences in contenthistid, and monitor for requests that include both contenthistid and previewID parameters. Limit administrative access, disable or tightly control plugin installation where feasible, and segment the CMS from sensitive internal systems. Because the content indicates active exploitation and available public tooling, temporary mitigations should be treated only as short-term risk reduction until vendor patches are applied.Patch, then assume compromise.
7.4.5, 7.3.12, and 7.2.7 contain a fix for this issue. However, the supporting content also references later patched versions 7.4.6, 7.3.13, and 7.2.8. Because the provided sources are inconsistent on exact fixed versions, defenders should verify the authoritative vendor advisory and install the latest available security release for their supported branch. After patching, review logs for requests to /_api/json/v1/default/?method=processAsyncObject, especially those containing suspicious contenthistid and previewID values, rotate administrative credentials and tokens if compromise is suspected, and inspect installed plugins for unauthorized additions or modified CFML files.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python script (CVE-2024-32640.py) and a README.md. The script is designed to detect and exploit a SQL injection vulnerability (CVE-2024-32640) in Mura CMS and Masa CMS. The exploit works by sending a crafted POST request to the /_api/json/v1/default/ endpoint with specific parameters, notably an escape sequence in the 'contenthistid' parameter, to trigger a SQL error and confirm the presence of the vulnerability. If the target is found vulnerable, the script can automate exploitation by invoking the Ghauri SQLi tool, allowing the attacker to extract data from the backend database. The README provides usage instructions, example commands, and additional context about the vulnerability and its impact. The main attack vector is network-based, targeting web servers running the affected CMS. The repository is operational, providing both detection and exploitation capabilities, but relies on an external tool (Ghauri) for full exploitation.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.