CVE-2015-20115 affects Next Click Ventures RealtyScript 4.0.2, stemming from improper sanitization of file uploads in admin/tools.php, which allows attackers to store malicious JavaScript. This medium-severity vulnerability (CVSS 6.1) is a Cross-Site Scripting (CWE-79) flaw, enabling unauthenticated attackers to execute scripts in the context of other users with low complexity. Exploitation requires user interaction, as another user must access the uploaded malicious file, potentially leading to low confidentiality and integrity impacts. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB, indicating very low community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.2CPE matchmatch criteria | cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.