CRITICAL🇵🇱 Wersja polska

CVE-2025-24297

CVSS 9.3v4.0pub. 2025-04-15upd. 2025-11-14

Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.

🤖 AI Analysis
How it works

The server does not properly validate user-entered data, allowing an attacker to place malicious JavaScript code in the portal's personal spaces. The injected code is then executed in the victim's browser when viewing the infected content. The attack does not require authentication, special privileges, or interaction from a system administrator beyond standard user operation.

Impact

An attacker can hijack a user session, steal authentication credentials or other sensitive information processed in the portal, and perform unauthorized actions on behalf of the victim. In the context of a portal managing energy infrastructure (photovoltaics), this can lead to violations of data confidentiality and integrity of installations.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. It is recommended to follow the CISA security advisory ICS Advisory ICSA-25-105-04 at https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04 and restrict portal access exclusively to trusted networks.

Who is affected

Growatt Cloud Portal — versions indicated in the manufacturer's references (ICS advisory ICSA-25-105-04)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Growatt Cloud Portal

    APP
    Growatt
    ≤ 3.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2025-30510CRITICAL9.3PL ✓same product

Growatt Cloud Portal — nieograniczony upload pliku zamiast obrazu instalacji

CVE-2025-30511HIGH8.7same product

An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value w...

CVE-2025-24850MEDIUM6.9same product

An attacker can export other users' plant information.

CVE-2025-26857MEDIUM6.9same product

Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).

CVE-2025-25276MEDIUM6.9same product

An unauthenticated attacker can hijack other users' devices and potentially control them.