CVE-2012-1979: Syndeocms
Low severity, CVSS 3.5. EPSS: 1.7% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the email parameter (aka Email address field) in an edit_user configuration action.
Affected products
- Syndeocms Syndeocms: up to and including 3.0.01; version 2.4 only; version 2.4.10 only; version 2.5.00 only; version 2.5.01 only; version 2.6.00 only; …
Published 2012-04-17. Last modified 2026-06-16.