CVE-2012-1203
SyndeoCMS < 3.0.00 - Cross-Site Request Forgery via User Account Creation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1203. PoCs published by Ivano Binetti.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in SyndeoCMS <= 3.0, allowing an attacker to create an admin account via a crafted HTML form. The form submits POST data to the target application, bypassing authentication checks.
Description
Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts via a save_user action.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in SyndeoCMS <= 3.0, allowing an attacker to create an admin account via a crafted HTML form. The form submits POST data to the target application, bypassing authentication checks.