LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2015-20114

nextclickventures · realtyscript

Published
CVSS6.1
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious input through multiple parameters that are not properly sanitized. Attackers can craft requests with injected script payloads in vulnerable parameters to execute code in users' browser sessions within the context of the affected application.

References

← Back to the CVE Tracker

Our coverage of CVE-2015-20114

No stories yet. This page updates automatically when we publish reporting that references CVE-2015-20114.