CVE-2015-7715
HIGHRealtyna RPL < 8.9.5 - Cross-Site Request Forgery via add_user Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-7715. PoCs published by Bikramaditya Guha.
AI-analyzed exploit summary The exploit demonstrates CSRF and stored XSS vulnerabilities in Realtyna RPL 8.9.2 Joomla extension. The CSRF PoC submits a form to perform administrative actions, while the XSS payloads inject malicious scripts via unsanitized POST parameters.
Description
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.
Exploits (1)
The exploit demonstrates CSRF and stored XSS vulnerabilities in Realtyna RPL 8.9.2 Joomla extension. The CSRF PoC submits a form to perform administrative actions, while the XSS payloads inject malicious scripts via unsanitized POST parameters.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H