ImpressCMS before 1.4.3 is vulnerable to SQL injection via the groups parameter in include/findusers.php, allowing unauthenticated attackers to execute arbitrary SQL queries.
id: CVE-2021-26599
info:
name: ImpressCMS < 1.4.3 - SQL Injection
author: ritikchaddha
severi
...