CVE-2015-20115Disclosure(nextclickventures / realtyscript)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • realtyscript

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
realtyscript

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Technical Details · 2026-03-16: 103-1603-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2015-20115 - Next Click Ventures - RealtyScript - https://www.redpacketsecurity.com/cve-alert-cve-2015-20115-next-click-ventures-realtyscript/ #OSINT #ThreatIntel #CyberSecurity #cve-2015-20115 #next-click-ventures #realtyscript

    Post summary

    The post alerts to CVE‑2015‑20115 affecting Next Click Ventures RealtyScript, linking to a security blog alert without providing further technical or operational details.

    0000060
    3.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2015-20115 Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin… https://www.cve.org/CVERecord?id=CVE-2015-20115

    Post summary

    The text announces CVE‑2015‑20115 for Next Click Ventures RealtyScript 4.0.2, detailing an unsanitized file upload vulnerability that permits script upload, with no evidence of exploitation, PoC, or patch.

    00000128
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnextclickventuresrealtyscript4.0.2--

Explore more