CVE-2015-20115: Nextclickventures Realtyscript

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.

Affected products

Published 2026-03-16. Last modified 2026-06-17.