VDB
Sign up
MEDIUM6.1

GHSA-xmhh-xrcc-mx36

Scrypted Cross-site Scripting vulnerability

Details

Scrypted is a home video integration and automation platform. In versions 0.55.0 and prior, a reflected cross-site scripting vulnerability exists in the plugin-http.ts file via the `owner' and 'pkg` parameters. An attacker can run arbitrary JavaScript code. As of time of publication, no known patches are available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@scrypted/server
Introduced in: 0

No fixed version published yet for @scrypted/server (npm). Pin to a known-safe version or switch to an alternative.

References