CVE-2021-26598: Medium severity impresscms vulnerability
Published Mar 28, 2022
·Updated
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).
Affected Software
1 affected component
ImpressCMS ImpressCMS<1.4.3
Event History
Mar 28, 2022
CVE Published
via MITRE·12:31 AM
Data Sourced
via MITRE·12:31 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-26598?
The severity of CVE-2021-26598 is medium with a CVSS score of 5.3.
2
How does CVE-2021-26598 impact ImpressCMS before 1.4.3?
CVE-2021-26598 impacts ImpressCMS before version 1.4.3 by allowing access to unauthenticated attackers through the include/findusers.php file.
3
What is the CWE for CVE-2021-26598?
The CWE for CVE-2021-26598 is CWE-287.