CVE-2021-26598

Publication date

2022-03-28 00:31:42

Family

mitre

State

PUBLISHED

Description

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).