SB2021032548 - Multiple vulnerabilities in Synapse



SB2021032548 - Multiple vulnerabilities in Synapse

Published: March 25, 2021 Updated: May 4, 2026

Security Bulletin ID SB2021032548
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2021-21333)

The vulnerability allows a remote user to inject forged content into notification emails.

The vulnerability exists due to improper neutralization of input during web page generation in email notification templates when rendering missed message notifications. A remote user can send crafted content to inject forged content into notification emails.

The account expiry notification path is also affected, but that injection is not controllable by an attacker.


2) Cross-site scripting (CVE-ID: CVE-2021-21332)

The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.

The vulnerability exists due to cross-site scripting in the password reset endpoint when handling password reset token submission. A remote attacker can send a specially crafted request to execute arbitrary script in the victim's browser.

The impact may include access to cookies and other browser data, CSRF exposure, and access to other resources served on the same domain or parent domains.


Remediation

Install update from vendor's website.