Stored Cross-Site Scripting Vulnerability in StockAgile by NovaDigits Technologies
CVE-2026-6084

5.1MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-6084?

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel, specifically at the REST endpoint '/inventory/configuration/variants'. This flaw allows an attacker to inject and persist malicious JavaScript code through parameters like 'code' and 'name' without proper filtering or validation. As a result, when authenticated users access the affected web panel, the injected scripts can be executed, leading to potential compromise of the user's session and sensitive data.

Affected Version(s)

StockAgile 0 < 25/09/2026

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel Jiménez Cámara
.