{"id":"CVE-2024-32642","summary":"Host header poisoning allows account takeover via password reset email","details":"Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6.","aliases":["GHSA-qjm6-c8hx-ffh8"],"modified":"2026-08-12T03:51:12.973591993Z","published":"2025-12-03T16:37:53.409Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-346","CWE-640"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32642.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32642.json"},{"type":"ADVISORY","url":"https://github.com/MasaCMS/MasaCMS/security/advisories/GHSA-qjm6-c8hx-ffh8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32642"},{"type":"FIX","url":"https://github.com/MasaCMS/MasaCMS/commit/7541b9c99fb9e32d1de6f2658750525cec1d8960"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/masacms/masacms","events":[{"introduced":"0"},{"fixed":"98222fa3679fde99e92c2c8c721e8040426e41f6"},{"introduced":"484759c901bb04016eb8493d31dcf9dcdf129020"},{"fixed":"2ebf767d40d04562417a0e0442d1c1988078a3c6"},{"introduced":"53d53e7c120068ce1102215805238ab19027fb58"},{"fixed":"fb10af6238e3e2e9aae8afce933ca6407d092fde"},{"fixed":"7541b9c99fb9e32d1de6f2658750525cec1d8960"}],"database_specific":{"cpe":"cpe:2.3:a:masacms:masacms:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.2.8"},{"introduced":"7.3"},{"fixed":"7.3.13"},{"introduced":"7.4.0"},{"fixed":"7.4.6"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["7.2.7","7.3.12","7.4.4","7.3.11","7.2.6","7.4.3","7.4.2","7.4.1","7.2.5","7.3.10","7.4.0","7.2.4","7.3.9","7.3.8","7.2.3","7.3.7","7.3.6","7.2.2","7.3.5","7.3.4","7.3.3","7.3.2","7.3.1","7.3","7.2.0","7.1.496","7.1.472","7.1.464","7.1.457","7.1.435","7.1.433","7.1.432","7.1.431","7.1.428","7.1.427","7.1.426","7.1.415","7.1.408","7.1.393","7.1.389","7.1.383","7.1.363","7.1.353","7.1.348","7.1.344","7.1.343","7.1.341","7.1.333","7.1.323","7.1.322","7.1.310","7.1.281","7.1.280","7.1.264","7.1.257","7.1.250","7.1.241","7.1.204","7.1.190","7.1.189","7.1.178","7.1.177","7.1.164","7.1.163","7.1.161","7.1.142","7.1.131","7.1.124","7.1.123","7.1.117","7.1.111","7.1.110","7.1.107","7.1.96","7.1.92","7.1.89","7.1.85","7.1.84","7.1.83","7.1.79","7.1.75","7.0.6967","7.0.6930","7.0.6919","6.2.6527","6.2.6161","5.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32642.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}