Stored Cross-Site Scripting Vulnerability in Stel Order by Stel Technology
CVE-2026-5790

5.1MEDIUM

Key Information:

Vendor

Stel Order

Vendor
CVE Published:
14 May 2026

What is CVE-2026-5790?

The vulnerability in Stel Order allows an attacker to exploit a stored XSS issue through the '/app/FrontController' endpoint using the 'legalName' and 'employeeID' parameters. Due to insufficient input sanitization, attackers can inject harmful scripts into the database. When accessed by users or administrators, these scripts execute in their browsers, potentially leading to session cookie theft and unauthorized access to accounts.

Affected Version(s)

Stel Order 0 <= 3.25.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David Padilla Alvarado
.