Impact
StockAgile, a product from Novadigits technologies, contains a stored cross‑site scripting flaw in an API that handles payment‑method data. Malicious JavaScript can be injected into fields such as "code" and "name" and then displayed in the management panel without proper sanitization. An attacker who has previously authenticated can use this vulnerability to run scripts in the browsers of other logged‑in users, enabling session theft, data exfiltration, or additional social‑engineering attacks.
Affected Systems
Only the Novadigits technologies StockAgile application is affected. The advisory specifies the ['/inventory/configuration/payment‑methods'] endpoint but does not provide explicit version information, so any deployment that uses this path is at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS data is unavailable and the vulnerability has not been listed in CISA KEV, suggesting limited public exploitation evidence. The flaw requires an authenticated user to submit malicious payloads to the vulnerable endpoint; once stored, the JavaScript executes in the browser of any user who views the injected data, potentially affecting all users with access to the panel.
OpenCVE Enrichment