ImpressCMS before 1.4.3 is susceptible to incorrect authorization via include/findusers.php. An attacker can provide a security token and potentially obtain sensitive information, modify data, and/or execute unauthorized operations.
View the template here CVE-2021-26598.yaml
References:
https://hackerone.com/reports/1081137