Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2681 | Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login. |
Github GHSA |
GHSA-ww7p-8gfg-v82r | Scrypted Cross-site Scripting vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T21:16:42.274Z
Reserved: 2023-11-07T16:57:49.243Z
Link: CVE-2023-47623
No data.
Status : Modified
Published: 2023-12-13T22:15:43.417
Modified: 2024-11-21T08:30:32.963
Link: CVE-2023-47623
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA