Stored XSS Vulnerability in Plant Management Tool by Vendor
CVE-2025-30511

8.7HIGH

Key Information:

Vendor

Growatt

Vendor
CVE Published:
15 April 2025

What is CVE-2025-30511?

An improper sanitization flaw in the plant name input during plant addition or editing allows an authenticated attacker to inject malicious scripts. This stored XSS vulnerability can lead to unauthorized data exposure or manipulation, posing a significant risk to users and the integrity of the application. Proper input validation and sanitization measures are essential to mitigate these risks.

Affected Version(s)

Cloud portal 0 < 3.6.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Forescout Technologies reported these vulnerabilities to CISA.
.