CVE-2015-20117

MEDIUM

RealtyScript 4.0.2 Cross-Site Request Forgery Unauthorized User Creation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-20117. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2, including user addition, privilege escalation to SUPERUSER, and persistent XSS via file upload and form parameters.

Description

Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to register new users with arbitrary credentials and escalate privileges to SUPERUSER level.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/38496

The exploit demonstrates multiple CSRF and stored XSS vulnerabilities in RealtyScript v4.0.2, including user addition, privilege escalation to SUPERUSER, and persistent XSS via file upload and form parameters.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: RealtyScript v4.0.2
Auth required
Prerequisites: Admin session cookies for CSRF attacks · Access to admin panel endpoints
devstral-2 · analyzed Mar 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-38496
https://www.exploit-db.com/exploits/38496
Third Party Advisory third-party-advisory
Zero Science Lab Disclosure
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5269.php
Third Party Advisory third-party-advisory
VulnCheck Advisory: RealtyScript 4.0.2 Cross-Site Request Forgery Unauthorized User Creation
https://www.vulncheck.com/advisories/realtyscript-cross-site-request-forgery-unauthorized-user-creation

Scores

CVSS v3 5.3
EPSS 0.0019
EPSS Percentile 9.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
Next Click Ventures/RealtyScript 4.0.2
nextclickventures/realtyscript 4.0.2
Published Mar 16, 2026
Tracked Since Mar 16, 2026