CVE-2025-24297
15.04.2025, 22:15
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
| Vendor | Product | Version |
|---|---|---|
| growatt | cloud_portal | 𝑥 ≤ 3.6.0 |
𝑥
= Vulnerable software versions