Stored Cross-Site Scripting Vulnerability in StockAgile API by NovaDigits Technologies
CVE-2026-6085
5.1MEDIUM
What is CVE-2026-6085?
A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel. This flaw is found on the server side specifically within the REST endpoint '/inventory/configuration/serial-number-types'. It allows an attacker to inject and store malicious JavaScript code through parameters such as ācodeā, ānameā, and various text fields. The application fails to properly filter or validate the input before displaying it on the web panel, accessible to authenticated users. Exploiting this vulnerability may enable a remote attacker to execute arbitrary JavaScript code in the context of an authenticated session, leading to potential data theft or session hijacking.
Affected Version(s)
StockAgile 0 < 25/09/2026
