CVE 9.3 CRITICAL

Masa CMS SQL injection via sortDirection parameter in beanFeed_CVE-2026-40330

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's handling of the sortDirection parameter. The parameter value is concatenated directly into SQL queries without sanitization or parameterization. An unauthenticated remote attacker can exploit this to extract sensitive information, modify or delete database records, or potentially achieve remote code execution on the underlying database server.

This issue has been fixed in versions 7.2.10, 7.3.15, 7.4.10, and 7.5.3. As a workaround, use a WAF to block or restrict access to the beanFeed.cfc component, or deploy rules to detect SQL injection patterns targeting the sortDirection parameter.

AI Analysis

SQL injection vulnerability in Masa CMS via the sortDirection parameter in the beanFeed.cfc component

Basic Information

ID CVE-2026-40330
Source GitHub_M
Published May 5, 2026 at 19:46

Affected Product

Vendor MasaCMS
Product MasaCMS
Version <= 7.2.9
Affected Versions MasaCMS MasaCMS <= 7.2.9
MasaCMS MasaCMS >= 7.3.0, <= 7.3.14
MasaCMS MasaCMS >= 7.4.0, <= 7.4.9
MasaCMS MasaCMS >= 7.5.0, <= 7.5.2

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor MasaCMS
Product Masa CMS
Version 7.2.0-7.2.9, 7.3.0-7.3.14, 7.4.0-7.4.9, 7.5.0-7.5.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.