Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 19 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextclickventures
Nextclickventures realtyscript |
|
| CPEs | cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Nextclickventures
Nextclickventures realtyscript |
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Next Click Ventures
Next Click Ventures realtyscript |
|
| Vendors & Products |
Next Click Ventures
Next Click Ventures realtyscript |
Sun, 15 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed. | |
| Title | RealtyScript 4.0.2 Stored Cross-Site Scripting via CSV File Upload Filename | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T14:30:31.280Z
Reserved: 2026-03-15T18:05:45.669Z
Link: CVE-2015-20116
Updated: 2026-03-16T14:21:16.415Z
Status : Analyzed
Published: 2026-03-16T14:17:47.077
Modified: 2026-03-19T14:12:28.390
Link: CVE-2015-20116
No data.
OpenCVE Enrichment
Updated: 2026-03-16T09:21:18Z