Record summary

CVE-2021-26598 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 1.4.3 · Fixed in 1.4.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMImpressCMS <1.4.3 - Incorrect AuthorizationCVSS 5.3

ImpressCMS before 1.4.3 is susceptible to incorrect authorization via include/findusers.php. An attacker can provide a security token and potentially obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can bypass authorization and gain unauthorized access to sensitive information or perform unauthorized actions.

Remediation

Upgrade to ImpressCMS version 1.4.3 or later to fix the vulnerability.

WeaknessesCWE-287
Authorsgy741, pdteam
Template tagscvecve2021hackeroneimpresscmsunauthcmsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:impresscms:impresscms:*:*:*:*:*:*:*:*
Shodan: http.html:"ImpressCMS"
Shodan: cpe:"cpe:2.3:a:impresscms:impresscms"
Shodan: http.html:"impresscms"
FOFA: body="impresscms"

Source: ProjectDiscovery

References

8