No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Next Click Ventures
Next Click Ventures realtyscript |
|
| Vendors & Products |
Next Click Ventures
Next Click Ventures realtyscript |
Sun, 15 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe payloads in the text parameter to store malicious content that executes in the browsers of users viewing the affected pages. | |
| Title | RealtyScript 4.0.2 Stored Cross-Site Scripting via text Parameter in pages.php | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T14:30:30.762Z
Reserved: 2026-03-15T18:06:49.812Z
Link: CVE-2015-20119
Updated: 2026-03-16T14:21:10.104Z
Status : Awaiting Analysis
Published: 2026-03-16T14:17:47.680
Modified: 2026-03-16T14:53:46.157
Link: CVE-2015-20119
No data.
OpenCVE Enrichment
Updated: 2026-03-16T09:21:13Z