S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jul 17, 2025

CVE-2024-9007 Scanner

CVE-2024-9007 Scanner - Cross-Site Scripting (XSS) vulnerability in 123Solar

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9007
5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the argument date1 leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 94bf9ab7ad0ccb7fbdc02f172f37f0e2ea08d48f. It is recommended to apply a patch to fix this issue.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
123solarby jeanmarc77
1.8.4.5
123solarby jeanmarc77
1.8.4.5
Updated Sep 10, 2026View on NVD →
Detail

123Solar is a popular solar panel monitoring software used by solar energy enthusiasts and professionals to monitor the status and performance of their solar panels. It facilitates real-time data analysis and visualization, making it a vital tool for efficient energy management. Users rely on 123Solar to track energy production, consumption metrics, and system performance. By providing detailed statistics and graphs, 123Solar aids in optimizing solar panel efficiency. The software is typically used in both residential and commercial solar installations. Its user-friendly interface and comprehensive monitoring capabilities make it a favored choice among its user base.

Cross-Site Scripting (XSS) is a vulnerability that allows an attacker to inject malicious scripts into web pages viewed by users. This reflected XSS vulnerability in 123Solar specifically targets the date1 parameter in detailed.php. Due to unsanitized user input, attackers can execute arbitrary JavaScript in the context of the victim's browser session. This vulnerability can potentially lead to session hijacking, credential theft, and other malicious activities. It is a severe security risk because attackers can manipulate and steal sensitive information. Addressing such vulnerabilities is crucial in preventing unauthorized actions and ensuring user safety.

Solution Advice
  • Update 123Solar to the latest version to address known vulnerabilities.
  • Implement proper input validation for all user-supplied data, with particular attention to the date1 parameter in detailed.php.
  • Use output encoding techniques to prevent reflected scripts from being executed in the user's browser.
  • Conduct regular security audits and penetration testing to identify and mitigate potential vulnerabilities.
  • Educate users about the importance of security practices and the potential dangers of clicking unknown links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-9007 Scanner - Cross-Site Scripting (XSS) vulnerability in 123Solar | S4E