Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 19 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextclickventures
Nextclickventures realtyscript |
|
| CPEs | cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Nextclickventures
Nextclickventures realtyscript |
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Next Click Ventures
Next Click Ventures realtyscript |
|
| Vendors & Products |
Next Click Ventures
Next Click Ventures realtyscript |
Sun, 15 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to register new users with arbitrary credentials and escalate privileges to SUPERUSER level. | |
| Title | RealtyScript 4.0.2 Cross-Site Request Forgery Unauthorized User Creation | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-16T14:30:31.130Z
Reserved: 2026-03-15T18:06:12.182Z
Link: CVE-2015-20117
Updated: 2026-03-16T14:21:14.325Z
Status : Analyzed
Published: 2026-03-16T14:17:47.260
Modified: 2026-03-19T14:13:34.260
Link: CVE-2015-20117
No data.
OpenCVE Enrichment
Updated: 2026-03-23T14:01:29Z