Description
Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database contents character by character based on response timing differences.
Published: 2026-03-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a time‑based blind SQL injection that exists in multiple application parameters of Next Click Ventures RealtyScript 4.0.2. It allows an unauthenticated attacker to embed SQL code that causes the database to delay its response. By measuring these timing differences the attacker can recover database data character by character. This flaw can lead to unauthorized disclosure of sensitive data stored in the database such as user credentials, property listings, and other confidential information. The weakness is identified as CWE‑89.

Affected Systems

The affected product is Next Click Ventures RealtyScript version 4.0.2. No other versions are listed as vulnerable. The product is identified by the CPE string cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*.

Risk and Exploitability

The CVSS score is 8.8, indicating a high severity that permits non‑authenticated attackers to obtain confidential data. The EPSS score is less than 1 %, implying lower current exploit probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote via HTTP requests; an attacker does not need authentication, but must be able to send crafted requests to the application’s vulnerable endpoints. The inability to get authenticated was explicitly stated in the description, making no additional prerequisites.

Generated by OpenCVE AI on March 19, 2026 at 15:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Next Click Ventures website for an official patch or update for RealtyScript 4.0.2.

Generated by OpenCVE AI on March 19, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 19 Mar 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Nextclickventures
Nextclickventures realtyscript
CPEs cpe:2.3:a:nextclickventures:realtyscript:4.0.2:*:*:*:*:*:*:*
Vendors & Products Nextclickventures
Nextclickventures realtyscript

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Next Click Ventures
Next Click Ventures realtyscript
Vendors & Products Next Click Ventures
Next Click Ventures realtyscript

Sun, 15 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Description Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database contents character by character based on response timing differences.
Title RealtyScript 4.0.2 Multiple Time-based Blind SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Next Click Ventures Realtyscript
Nextclickventures Realtyscript
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-16T14:20:17.335Z

Reserved: 2026-03-15T18:07:08.695Z

Link: CVE-2015-20120

cve-icon Vulnrichment

Updated: 2026-03-16T14:17:07.956Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-16T14:17:47.957

Modified: 2026-03-19T14:15:53.783

Link: CVE-2015-20120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T14:01:18Z

Weaknesses