PT-2026-98414 · Unknown · Stockagile

CVE-2026-6086

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions StockAgile (affected versions not specified)
Description Stored Cross-Site Scripting (XSS) occurs in the API and management panel. The issue exists on the server side within the '/inventory/configuration/serial-number-types' endpoint, where malicious JavaScript code can be injected and persisted via the code and name parameters, as well as other text fields. Because the input is not correctly filtered or validated before being displayed on the web panel, an authenticated remote attacker can execute arbitrary JavaScript code in the context of other authenticated users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the code and name parameters in the '/inventory/configuration/serial-number-types' endpoint until the issue is resolved.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6086

Affected Products

Stockagile