PT-2026-25720 · Nextclickventures · Realtyscript

Published

2026-03-15

·

Updated

2026-03-16

·

CVE-2015-20117

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RealtyScript version 4.0.2
Description RealtyScript 4.0.2 contains a cross-site request forgery issue that allows unauthenticated attackers to create unauthorized user accounts and administrative users. Attackers can craft malicious forms to submit hidden form data to the following API endpoints: /admin/addusers.php and /admin/editadmins.php. This allows them to register new users with arbitrary credentials and escalate privileges to the SUPERUSER level.
Recommendations Apply a fix to address the cross-site request forgery issue in the /admin/addusers.php and /admin/editadmins.php endpoints.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2015-20117

Affected Products

Realtyscript