CVE-2023-47620

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-47620
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-47620.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-47620
Aliases
Published
2023-12-13T22:15:43Z
Modified
2025-09-19T14:43:14.076635Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the plugin-http.ts file via the owner' and 'pkg parameters. An attacker can run arbitrary JavaScript code.

References

Affected packages

Git / github.com/koush/scrypted

Affected ranges

Type
GIT
Repo
https://github.com/koush/scrypted
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v0.*

v0.21.0
v0.23.0
v0.39.0
v0.41.0
v0.50.0
v0.51.0
v0.55.0
v0.6.20
v0.6.22
v0.6.23
v0.6.24
v0.6.26
v0.7.10
v0.7.11
v0.7.12
v0.7.13
v0.7.15
v0.7.16
v0.7.27
v0.7.28
v0.7.32
v0.7.35
v0.7.36
v0.7.37
v0.7.4
v0.7.40
v0.7.41
v0.7.42
v0.7.44
v0.7.45
v0.7.46
v0.7.5
v0.7.51
v0.7.52
v0.7.53
v0.7.6
v0.7.7
v0.7.77
v0.7.8
v0.7.80
v0.7.81
v0.7.84
v0.7.85
v0.7.9
v0.7.90
v0.7.92
v0.7.94
v0.7.95
v0.7.97