CVE-2015-20115
HIGHRealtyScript 4.0.2 Stored Cross-Site Scripting via File Upload Parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2015-20115. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2. It includes functional PoC code for uploading malicious CSV files, adding users, creating superusers, and injecting XSS payloads via various parameters.
Description
Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.
Exploits (1)
The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2. It includes functional PoC code for uploading malicious CSV files, adding users, creating superusers, and injecting XSS payloads via various parameters.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N