google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

PRP: Request SQLi in Mura/Masa CMS (CVE-2024-32640) #497

Open W0ngL1 opened 3 weeks ago

W0ngL1 commented 3 weeks ago

Hi there.

I would like to start implementing a plugin to detect SQLi in Mura/Masa CMS (CVE-2024-32640). This vulnerability was published on May 2024, and Apple has been hacked cause this vulnerability, https://blog.projectdiscovery.io/hacking-apple-with-sql-injection/.

References: https://nvd.nist.gov/vuln/detail/CVE-2024-32640 https://blog.projectdiscovery.io/hacking-apple-with-sql-injection/

Description: Mura CMS and Masa CMS are content management systems designed to facilitate the creation, management, and deployment of digital content for websites and web applications. Both CMS platforms offer robust features tailored to different needs, though they share some common capabilities.

Affected Versions: Masa CMS < 7.4.6/7.3.13/7.2.8

Thanks.