Executive brief
Scrypted is a home video integration and automation platform used to manage and automate video systems in residential and commercial environments. The login page contains a reflected cross-site scripting vulnerability in the redirect_uri parameter that allows an attacker to inject and execute arbitrary JavaScript code after a user logs in, potentially compromising user credentials or session tokens.
Technical details
A reflected cross-site scripting (CWE-79) vulnerability exists in the Scrypted login page via the redirect_uri parameter, which fails to properly sanitize URLs with the javascript: scheme. An attacker can craft a malicious login link containing a javascript: URL in the redirect_uri parameter, which executes arbitrary JavaScript in the user's browser context after successful authentication. The vulnerability requires user interaction (clicking a malicious link and logging in) and is network-reachable without authentication. As of the advisory publication date, no patches are available.
Affected products
- Scrypted @scrypted/core 0.1.142 and prior
Timeline
- 2023-12-13: disclosed: CVE-2023-47623 published to NVD
- 2024-08-05: advisory: GHSA-ww7p-8gfg-v82r advisory published