CVE-2025-36750: Stored cross site scripting (XSS) vulnerability in Growatt ShineLan-X
ShineLan-X contains a stored cross site scripting (XSS) vulnerability in the Plant Name field. A HTML payload will be displayed on the plant management page via a direct post. This may allow attackers to force a legitimate user’s browser’s JavaScript engine to run malicious code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36750?
CVE-2025-36750 is classified as a moderate severity vulnerability due to its potential for stored cross site scripting (XSS).
How do I fix CVE-2025-36750?
To fix CVE-2025-36750, sanitize and validate user inputs for the Plant Name field to prevent execution of HTML payloads.
What is the impact of CVE-2025-36750?
The impact of CVE-2025-36750 includes the potential for attackers to execute arbitrary JavaScript in the context of a victim's browser.
Who is affected by CVE-2025-36750?
Users of the Growatt ShineLan-X product are affected by CVE-2025-36750, specifically any version that allows direct posting to the Plant Name field.
What type of vulnerability is CVE-2025-36750?
CVE-2025-36750 is a stored cross site scripting (XSS) vulnerability.