ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17551
Reference (s):
- https://github.com/ImpressCMS/impresscms/issues/659
- https://www.impresscms.org/

