PT-2026-25720 · Nextclickventures · Realtyscript
Published
2026-03-15
·
Updated
2026-03-16
·
CVE-2015-20117
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RealtyScript version 4.0.2
Description
RealtyScript 4.0.2 contains a cross-site request forgery issue that allows unauthenticated attackers to create unauthorized user accounts and administrative users. Attackers can craft malicious forms to submit hidden form data to the following API endpoints:
/admin/addusers.php and /admin/editadmins.php. This allows them to register new users with arbitrary credentials and escalate privileges to the SUPERUSER level.Recommendations
Apply a fix to address the cross-site request forgery issue in the
/admin/addusers.php and /admin/editadmins.php endpoints.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realtyscript