CVE-2015-20116
MEDIUMRealtyScript 4.0.2 Stored Cross-Site Scripting via CSV File Upload Filename
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2015-20116. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2. It includes functional PoC code for uploading malicious files, adding users, and injecting scripts via various parameters.
Description
Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed.
Exploits (1)
The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2. It includes functional PoC code for uploading malicious files, adding users, and injecting scripts via various parameters.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N