Impact
StockAgile contains a stored cross‑site scripting flaw in the inventory configuration API. Malicious JavaScript can be injected via the 'code', 'name', and other text fields and persists in the database. When an authenticated user views the management panel, the unsanitized script runs in their browser, enabling arbitrary code execution within that user’s context.
Affected Systems
Novadigits technologies offers the StockAgile platform. The flaw resides in the server‑side REST endpoint '/inventory/configuration/categories' of StockAgile’s API and the web‑panel. No specific major versions are listed, so all deployed instances that expose this endpoint are potentially affected.
Risk and Exploitability
The CVSS score is 5.1, reflecting a medium severity due to the requirement of prior authentication and the need for a user to load the panel. The EPSS score is unavailable, so exploitation likelihood cannot be quantified. Because the vulnerability is not in the CISA KEV catalog, it is not known to be actively exploited. Attackers would need to be authenticated and access the panel to run the embedded script, but they could hijack existing sessions, deface pages, or pull other data. This indicates a moderate risk for organizations that rely on StockAgile without mitigating input sanitization.
OpenCVE Enrichment