CVE-2015-20116

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*

History

19 Mar 2026, 14:12

Type Values Removed Values Added
CPE cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*
Summary
  • (es) Next Click Ventures RealtyScript 4.0.2 no sanea correctamente las subidas de archivos CSV, permitiendo a los atacantes inyectar scripts maliciosos a través de parámetros de nombre de archivo en datos de formulario multipart. Los atacantes pueden subir archivos con cargas útiles de XSS en el campo de nombre de archivo para ejecutar JavaScript arbitrario en los navegadores de los usuarios cuando el archivo es procesado o mostrado.
References () https://www.exploit-db.com/exploits/38496 - () https://www.exploit-db.com/exploits/38496 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/realtyscript-stored-cross-site-scripting-via-csv-file-upload-filename - () https://www.vulncheck.com/advisories/realtyscript-stored-cross-site-scripting-via-csv-file-upload-filename - Third Party Advisory
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5269.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5269.php - Exploit, Third Party Advisory
First Time Nextclickventures realtyscript
Nextclickventures

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-03-19 14:12


NVD link : CVE-2015-20116

Mitre link : CVE-2015-20116

CVE.ORG link : CVE-2015-20116


JSON object : View

Products Affected

nextclickventures

  • realtyscript
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')