Impact
A stored cross‑site scripting flaw was found in the StockAgile application’s REST endpoint '/inventory/configuration/serial-number-types'. Parameters such as 'code', 'name' and other textual fields accept user input that is saved to the database without proper sanitization or output encoding. When a user views the affected data through the web panel, the malicious JavaScript is rendered in the browser, enabling an attacker to run arbitrary script in the context of that user.
Affected Systems
Novadigits technologies’ StockAgile product is affected via its API. No specific product versions are listed in the advisory, so any deployment that incorporates the vulnerable endpoint may be impacted.
Risk and Exploitability
The CVSS base score is 5.1, indicating medium severity. EPSS is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a remotely authenticated attacker who can inject payloads via the exposed API; the attacker can then coerce other authenticated users into executing the stored script when they access the management panel. The risk, while not high to prevent all exploitation, is sufficient to warrant timely mitigation.
OpenCVE Enrichment