VYPR
Unrated severityNVD Advisory· Published Mar 15, 2026· Updated Mar 16, 2026

RealtyScript 4.0.2 Stored Cross-Site Scripting via CSV File Upload Filename

CVE-2015-20116

Description

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.