CVE detail
CVE-2023-47623 — CVE-2023-47623
Published 2023-12-13 · Modified 2026-06-17 · Vendor clockworkmod · Product scrypted · Source nvd
MEDIUM
severity
CVSS-derived band
0.0042
EPSS probability
exploitation probability, 30d
35.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the login page via the `redirect_uri` parameter. By specifying a url with the javascript scheme (`javascript:`), an attacker can run arbitrary JavaScript code after the login.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References