Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
The server does not properly validate user-entered data, allowing an attacker to place malicious JavaScript code in the portal's personal spaces. The injected code is then executed in the victim's browser when viewing the infected content. The attack does not require authentication, special privileges, or interaction from a system administrator beyond standard user operation.
An attacker can hijack a user session, steal authentication credentials or other sensitive information processed in the portal, and perform unauthorized actions on behalf of the victim. In the context of a portal managing energy infrastructure (photovoltaics), this can lead to violations of data confidentiality and integrity of installations.
Patches available from the manufacturer should be applied according to the references. It is recommended to follow the CISA security advisory ICS Advisory ICSA-25-105-04 at https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04 and restrict portal access exclusively to trusted networks.
Growatt Cloud Portal — versions indicated in the manufacturer's references (ICS advisory ICSA-25-105-04)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGrowatt Cloud Portal
APPGrowatt≤ 3.6.0
Related vulnerabilities
Growatt Cloud Portal — nieograniczony upload pliku zamiast obrazu instalacji
An authenticated attacker can achieve stored XSS by exploiting improper sanitization of the plant name value w...
An attacker can export other users' plant information.
Unauthenticated attackers can rename arbitrary devices of arbitrary users (i.e., EV chargers).
An unauthenticated attacker can hijack other users' devices and potentially control them.