S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-26598 Scanner

CVE-2021-26598 scanner - Improper Access Control vulnerability in ImpressCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-26598
5.3
CVSS

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

ImpressCMS is a popular content management system that allows website owners to easily create and manage their online presence. It is designed to cater to the needs of both novice and advanced users, offering a wide range of features including customizable templates, multiple language support, and modular architecture. 

CVE-2021-26598 is a recently discovered vulnerability in ImpressCMS, which allows unauthenticated attackers to gain access to the system through the include/findusers.php file. This means that anyone with a security token can exploit this vulnerability and gain unauthorized access to the system, resulting in compromised website security.

If this vulnerability is exploited, it can lead to a range of malicious activities such as unauthorized content editing, defacing of the website, and theft of sensitive information like usernames and passwords. This can have a significant impact on the online reputation of the website, as well as cause reputational harm to the owner of the website.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a range of security tools and services to help website owners protect their online security, including vulnerability scanning, malware detection, and real-time threat monitoring. By utilizing these tools, users can stay ahead of potential security threats and ensure their online presence remains secure and protected.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of ImpressCMS can take the following precautions:

  • Update the system to version 1.4.3 or higher, as this specific vulnerability has been patched in the latest version
  • Remove or restrict access to the include/findusers.php file
  • Utilize strong passwords and enable two-factor authentication
  • Regularly scan the website for vulnerabilities and suspicious activity
  • Backup the website regularly to prevent data loss in case of a breach

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.