Stored Cross-Site Scripting Vulnerability in StockAgile API by NovaDigits Technologies
CVE-2026-6085

5.1MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-6085?

A stored Cross-Site Scripting (XSS) vulnerability exists in the StockAgile API and management panel. This flaw is found on the server side specifically within the REST endpoint '/inventory/configuration/serial-number-types'. It allows an attacker to inject and store malicious JavaScript code through parameters such as ā€˜code’, ā€˜name’, and various text fields. The application fails to properly filter or validate the input before displaying it on the web panel, accessible to authenticated users. Exploiting this vulnerability may enable a remote attacker to execute arbitrary JavaScript code in the context of an authenticated session, leading to potential data theft or session hijacking.

Affected Version(s)

StockAgile 0 < 25/09/2026

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Miguel JimƩnez CƔmara
.