CVE-2025-24297: Growatt Cloud portal Cross-site Scripting
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24297?
CVE-2025-24297 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2025-24297?
To fix CVE-2025-24297, it is essential to implement server-side input validation and encode user inputs properly.
What impact does CVE-2025-24297 have on users?
CVE-2025-24297 allows attackers to inject malicious JavaScript, potentially compromising user data and privacy.
Is there a patch available for CVE-2025-24297?
Currently, there is no official patch for CVE-2025-24297; however, users should keep their software updated and apply any available security measures.
Who is affected by CVE-2025-24297?
CVE-2025-24297 affects users of the Growatt Cloud Portal version 3.6.0 and earlier due to its lack of input validation.