LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2015-20116

nextclickventures · realtyscript

Published
CVSS6.1
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is processed or displayed.

References

← Back to the CVE Tracker

Our coverage of CVE-2015-20116

No stories yet. This page updates automatically when we publish reporting that references CVE-2015-20116.