CVE-2025-36746: SolarEdge Monitoring Platform contains a XSS upon report deletion
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36746?
CVE-2025-36746 is classified as a high severity vulnerability due to its potential for exploitation via Cross-Site Scripting (XSS).
How do I fix CVE-2025-36746?
To mitigate CVE-2025-36746, ensure that input sanitization and output encoding are implemented to prevent XSS attacks in report names.
Who is affected by CVE-2025-36746?
The vulnerability affects all authenticated users of the SolarEdge Monitoring Platform who can inject payloads into report names.
What kind of attack can be performed using CVE-2025-36746?
CVE-2025-36746 allows an authenticated user to execute Cross-Site Scripting attacks in a victim’s browser during the deletion of reports.
Is CVE-2025-36746 under active exploitation?
As of now, there are no public reports confirming active exploitation of CVE-2025-36746, but it is recommended to apply mitigations promptly.