SunGrow iSolarCloud Insecure Direct Object Reference Vulnerability in userService API
Vulnerability
A vulnerability allowing Insecure Direct Object References (IDOR) has been identified in the SunGrow iSolarCloud userService API, prior to the October 31, 2024 remediation. This vulnerability enables unauthorized access to sensitive user account data, potentially leading to data leakage and privacy violations.
Impact
Exploitation of this vulnerability could result in unauthorized access to user account information, causing data leakage and privacy breaches.
Remediation
SunGrow iSolarCloud has been automatically updated and repaired on October 31, 2024. Customers are advised to implement security updates in a timely manner.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
