SyndeoCMS Multiple Cross Site Scripting and SQL Injection Vulnerabilities

Summary
SyndeoCMS is prone to multiple cross-site scripting vulnerabilities and an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to steal cookie- based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. SyndeoCMS 2.8.02 is vulnerable other versions may also be affected.
References