Stored Cross-Site Scripting Vulnerability in StockAgile by NovaDigits Technologies
CVE-2026-6084
5.1MEDIUM
What is CVE-2026-6084?
A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically at the REST endpoint '/inventory/configuration/variants'. This flaw allows an attacker to inject and persist malicious JavaScript code through parameters like 'code' and 'name' without proper filtering or validation. As a result, when authenticated users access the affected web panel, the injected scripts can be executed, leading to potential compromise of the user's session and sensitive data.
Affected Version(s)
StockAgile 0 < 25/09/2026
