PT-2026-98416 · Unknown · Stockagile
CVE-2026-6088
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
StockAgile (affected versions not specified)
Description
Stored Cross-Site Scripting (XSS) occurs in the API and management panel. The issue exists on the server side within the '/inventory/configuration/categories' endpoint, where malicious JavaScript code can be injected and persisted via the
code and name parameters, as well as other text fields. This happens because input is not correctly filtered or validated before being displayed to authenticated users on the web panel. A remote, authenticated attacker could exploit this to execute arbitrary JavaScript code.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
code and name parameters in the '/inventory/configuration/categories' endpoint until the issue is resolved.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stockagile