CVE-2021-26600: Critical severity impresscms vulnerability
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26600?
CVE-2021-26600 is a vulnerability in ImpressCMS before 1.4.3 that allows for an authentication bypass due to type confusion in the autologin.php plugin.
How severe is CVE-2021-26600?
CVE-2021-26600 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
What software versions are affected by CVE-2021-26600?
ImpressCMS versions up to and excluding 1.4.3 are affected by CVE-2021-26600.
How can I fix CVE-2021-26600?
To fix CVE-2021-26600, update your ImpressCMS installation to version 1.4.3 or later.
Where can I find more information about CVE-2021-26600?
You can find more information about CVE-2021-26600 at the following references: [link1](http://karmainsecurity.com/KIS-2022-01), [link2](http://packetstormsecurity.com/files/166393/ImpressCMS-1.4.2-Authentication-Bypass.html), [link3](http://seclists.org/fulldisclosure/2022/Mar/43).