CVE-2025-24297
Severity CVSS v4.0:
CRITICAL
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
15/04/2025
Last modified:
14/11/2025
Description
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:growatt:cloud_portal:*:*:*:*:*:*:*:* | 3.6.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



