#VU61535 Improper access control in ImpressCMS - CVE-2021-26598
Published: March 22, 2022 / Updated: May 13, 2022
ImpressCMS
The ImpressCMS Project
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within "/include/findusers.php" file. A remote attacker can bypass implemented security restrictions and obtain sensitive information about application users.