Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-12-13T21:38:14.451Z
Updated: 2024-08-02T21:16:42.274Z
Reserved: 2023-11-07T16:57:49.243Z
Link: CVE-2023-47623
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-13T22:15:43.417
Modified: 2024-11-21T08:30:32.963
Link: CVE-2023-47623
Redhat
No data.