Vulnerability Details CVE-2025-24297
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.6%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-24297
-
cpe:2.3:a:growatt:cloud_portal:*