This advisory details a blind SQL injection vulnerability in Symphony CMS 2.1.2 and earlier, where the login page fails to properly sanitize the 'token' parameter. The writeup includes a proof-of-concept URL demonstrating password reset abuse via SQLi.