Description
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
unkown
Credits
Akram Hamdi (ENCS)
Victor Pasman (DIVD)
References
csirt.divd.nl/CVE-2025-36746
csirt.divd.nl/DIVD-2025-00022/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.