Impact
The vulnerability in Next Click Ventures RealtyScript 4.0.2 enables an authenticated attacker to submit malicious content through the text parameter in the pages.php admin interface. The stored payload can include iframe tags or other HTML that will be rendered when viewers access the affected page, resulting in the execution of client‑side scripts in those browsers.
Affected Systems
The affected product is Next Click Ventures RealtyScript version 4.0.2. No other versions or products are listed as vulnerable in the provided data.
Risk and Exploitability
The CVSS v3 score of 5.1 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the admin interface, but once the malicious page is stored, any user who visits that page can be impacted, resulting in a moderate overall risk.
OpenCVE Enrichment