CVE-2012-1203

SyndeoCMS < 3.0.00 - Cross-Site Request Forgery via User Account Creation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-1203. PoCs published by Ivano Binetti.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in SyndeoCMS <= 3.0, allowing an attacker to create an admin account via a crafted HTML form. The form submits POST data to the target application, bypassing authentication checks.

Description

Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts via a save_user action.

Exploits (1)

exploitdb WORKING POC
by Ivano Binetti · htmlwebappsphp
https://www.exploit-db.com/exploits/18498

This exploit demonstrates a CSRF vulnerability in SyndeoCMS <= 3.0, allowing an attacker to create an admin account via a crafted HTML form. The form submits POST data to the target application, bypassing authentication checks.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: SyndeoCMS <= 3.0
No auth needed
Prerequisites: Victim must visit the malicious HTML page while authenticated to the target SyndeoCMS instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18498/

Scores

EPSS 0.0106
EPSS Percentile 60.0%

Details

CWE
CWE-352
Status published
Products (1)
syndeocms/syndeocms < 3.0.00
Published Dec 28, 2014
Tracked Since Feb 18, 2026