CVE-2023-47620

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/12/2023
Last modified:
13/02/2024

Description

Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the plugin-http.ts file via the `owner' and 'pkg` parameters. An attacker can run arbitrary JavaScript code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clockworkmod:scrypted:*:*:*:*:*:*:*:* 0.55.0 (including)