CVE-2015-20117
MEDIUMRealtyScript 4.0.2 Cross-Site Request Forgery Unauthorized User Creation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2015-20117. PoCs published by LiquidWorm.
AI-analyzed exploit summary The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2, including user addition, privilege escalation to SUPERUSER, and persistent XSS via file upload and form parameters.
Description
Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to register new users with arbitrary credentials and escalate privileges to SUPERUSER level.
Exploits (1)
The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2, including user addition, privilege escalation to SUPERUSER, and persistent XSS via file upload and form parameters.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N