Stored Cross-Site Scripting Vulnerability in StockAgile API by NovaDigits Technologies
CVE-2026-6082
5.1MEDIUM
What is CVE-2026-6082?
The StockAgile API contains a stored Cross-Site Scripting (XSS) vulnerability due to insufficient input validation on the server side. This flaw is located within the REST endpoint '/inventory/configuration/payment-methods', where parameters such as 'code' and 'name' can be manipulated to inject malicious JavaScript code. Since the entered scripts are inadequately filtered, authenticated users accessing the management panel may unknowingly execute this code, permitting potential attackers to compromise user data and application confidentiality.
Affected Version(s)
StockAgile 0 < 25/09/2026
