Medium severity6.1NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026
CVE-2015-20116
CVE-2015-20116
Description
Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*
- (no CPE)range: =4.0.2
- (no CPE)range: 4.0.2
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/38496nvdExploitThird Party AdvisoryVDB Entry
- www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5269.phpnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/realtyscript-stored-cross-site-scripting-via-csv-file-upload-filenamenvdThird Party Advisory
News mentions
0No linked articles in our index yet.