CVE-2012-1979: Syndeocms

Low severity, CVSS 3.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the email parameter (aka Email address field) in an edit_user configuration action.

Affected products

  • Syndeocms Syndeocms: up to and including 3.0.01; version 2.4 only; version 2.4.10 only; version 2.5.00 only; version 2.5.01 only; version 2.6.00 only; …

Published 2012-04-17. Last modified 2026-06-16.