PT-2026-98412 · Unknown · Stockagile
CVE-2026-6084
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
StockAgile (affected versions not specified)
Description
Stored Cross-Site Scripting (XSS) occurs in the API and management panel. The issue exists on the server side within the REST endpoint '/inventory/configuration/variants', where malicious JavaScript code can be injected and persisted via parameters such as
code, name, and other text fields. Because the input is not correctly filtered or validated before being displayed on the web panel, a remote authenticated attacker can execute arbitrary JavaScript code in the context of other authenticated users.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
code and name parameters in the '/inventory/configuration/variants' endpoint until the issue is resolved.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stockagile