Impact
Stored Cross‑Site Scripting exists in the StockAgile API and management panel, allowing a malicious user to inject arbitrary JavaScript through fields such as ‘code’ and ‘name’. The injected code is stored and later displayed on the web panel without proper filtering, enabling an authenticated attacker to execute scripts in the context of the victim’s browser. This could lead to session hijacking, defacement or data exfiltration within the privileged scope of the authenticated user.
Affected Systems
Novadigits technologies’ StockAgile platform is affected. The vulnerability resides in the REST endpoint '/inventory/configuration/categories'. No specific product versions are listed, so any deployment exposing this endpoint is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the absence of an EPSS score or KEV listing suggests no publicly documented exploits yet. The vulnerability requires prior authentication but can be abused by an attacker who has legitimate credentials to inject malicious scripts that run in the victim’s browser context. Attackers could hijack sessions, deface content, or exfiltrate data within the authenticated user’s permissions.
OpenCVE Enrichment