CVE-2021-26599: SQL Injection
Published Mar 28, 2022
·Updated
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
Affected Software
1 affected component
ImpressCMS ImpressCMS<1.4.4
Event History
Mar 28, 2022
CVE Published
via MITRE·12:41 AM
Data Sourced
via MITRE·12:41 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-26599?
CVE-2021-26599 is classified as a critical vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2021-26599?
To fix CVE-2021-26599, upgrade to ImpressCMS version 1.4.3 or later.
3
What impact does CVE-2021-26599 have on my system?
CVE-2021-26599 can allow an attacker to execute arbitrary SQL queries, compromising the integrity of the database.
4
Where is CVE-2021-26599 found in ImpressCMS?
CVE-2021-26599 affects the include/findusers.php file in ImpressCMS versions prior to 1.4.3.
5
Is my system vulnerable to CVE-2021-26599 if I use an unsupported version of ImpressCMS?
Yes, using any version of ImpressCMS prior to 1.4.3 makes your system vulnerable to CVE-2021-26599.