Executive brief
Vizly Web Design Real Estate Packages, a software suite used for building and managing real estate websites, contains a security flaw that could allow attackers to manipulate website content. By tricking a user into clicking a malicious link, an attacker could steal sensitive session information or display fraudulent information to visitors. This could lead to unauthorized account access and damage to the business's reputation.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Vizly Web Design Real Estate Packages prior to version 5.1 due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by inducing a user to visit a specially crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking (CAPEC-593), content spoofing, and unauthorized data access. The vulnerability is addressed in version 5.1.
Affected products
- Vizly Web Design Real Estate Packages before 5.1
Timeline
- 2025-09-19: disclosed
- 2025-09-19: advisory