Junglewise Threat Intelligence

CVE-2023-47623: Scrypted Cross-site Scripting in login page

CVE-2023-47623 · Severity: low · CVSS 3.1 · Published 2024-08-05

Vendors: npm.

Executive brief

Scrypted is a home video integration and automation platform used to manage and automate video systems in residential and commercial environments. The login page contains a reflected cross-site scripting vulnerability in the redirect_uri parameter that allows an attacker to inject and execute arbitrary JavaScript code after a user logs in, potentially compromising user credentials or session tokens.

Technical details

A reflected cross-site scripting (CWE-79) vulnerability exists in the Scrypted login page via the redirect_uri parameter, which fails to properly sanitize URLs with the javascript: scheme. An attacker can craft a malicious login link containing a javascript: URL in the redirect_uri parameter, which executes arbitrary JavaScript in the user's browser context after successful authentication. The vulnerability requires user interaction (clicking a malicious link and logging in) and is network-reachable without authentication. As of the advisory publication date, no patches are available.

Affected products

  • Scrypted @scrypted/core 0.1.142 and prior

Timeline

  • 2023-12-13: disclosed: CVE-2023-47623 published to NVD
  • 2024-08-05: advisory: GHSA-ww7p-8gfg-v82r advisory published

References

Related threats