Server-side Input Validation Flaw in Web Portal by Vendor
CVE-2025-24297

9.3CRITICAL

Key Information:

Vendor

Growatt

Vendor
CVE Published:
15 April 2025

What is CVE-2025-24297?

A security flaw has been identified in the web portal, allowing unauthorized users to exploit the lack of server-side input validation. This vulnerability enables attackers to inject malicious JavaScript code into the personal spaces of users, posing significant risks, including data theft and unauthorized actions within the application. Organizations are urged to review their web portal implementations and ensure proper input validation mechanisms are in place to mitigate potential attacks.

Affected Version(s)

Cloud portal 0 < 3.6.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Forescout Technologies reported these vulnerabilities to CISA.
.
CVE-2025-24297 : Server-side Input Validation Flaw in Web Portal by Vendor