RealtyScript 4.0.2 Stored Cross-Site Scripting via File Upload Parameter
Vulnerability Description
Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-20115
Credits & Attribution
No credits recorded in the NVD database.
References
More from Next Click Ventures
View All →Affected Vendor
Next Click Ventures
View all reports →