CVE-2023-47623

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/12/2023
Last modified:
13/02/2024

Description

Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clockworkmod:scrypted:*:*:*:*:*:*:*:* 0.55.0 (including)