Skip to content

Stored Cross-Site Scripting Vulnerability in StockAgile by Novadigits Technologies

Published:
Stored Cross-Site Scripting Vulnerability in StockAgile by Novadigits Technologies

Original source: Stored Cross-Site Scripting in StockAgile by Novadigits Technologies.

INCIBE has coordinated the publication of seven medium-severity vulnerabilities affecting StockAgile, software by Novadigits Technologies for managing stores, e-commerce, and warehouses. Among them is a stored Cross-Site Scripting vulnerability that impacts the API and the StockAgile administration panel.

Discovery and Characteristics of the Vulnerability

The vulnerability was discovered by Miguel Jiménez Cámara. It is located on the server side, across various REST endpoints, and involves the injection and persistence of malicious JavaScript code through parameters such as ‘code’, ‘name’, and other text fields. This code is not properly filtered or validated before being displayed on the web panel accessed by authenticated users.

Exploitation would allow a remote attacker with authenticated access to execute arbitrary JavaScript code within the application.

Affected Endpoints and Technical Details

Stored Cross-Site Scripting Vulnerability in StockAgile by Novadigits Technologies

The vulnerabilities are identified with the following CVEs and endpoints:

  • CVE-2026-6082: /inventory/configuration/payment-methods
  • CVE-2026-6083: /inventory/configuration/pricing-tiers
  • CVE-2026-6084: /inventory/configuration/variants
  • CVE-2026-6085: /inventory/configuration/serial-number-types
  • CVE-2026-6086: /inventory/configuration/seasons
  • CVE-2026-6087: /inventory/configuration/categories
  • CVE-2026-6088: /inventory/configuration/brands

These vulnerabilities have a base CVSS v4.0 score of 5.1 and are categorized under the CWE-79 code.

Current Status and Solutions

No official solution has been reported by Novadigits Technologies to mitigate these vulnerabilities.

INCIBE has issued this early alert to inform about the risks posed by these vulnerabilities.

Implications for Users and Administrators

The stored Cross-Site Scripting could allow the execution of malicious code in the StockAgile administration panel, potentially affecting session security and displayed data.

The alert does not specify additional impacts or concrete measures beyond monitoring and awaiting a fix from the vendor.

Context and Scope of the Stored Cross-Site Scripting Vulnerability in StockAgile

The stored Cross-Site Scripting vulnerability detected in StockAgile affects both the API and the administration panel of the software, used for managing stores, e-commerce, and warehouses. This vulnerability exists on the server side and allows the persistent injection of malicious JavaScript code through specific parameters, such as ‘code’ and ‘name’, among other text fields. This malicious code is not adequately filtered or validated before being displayed on the web panel, exposing authenticated users to the execution of arbitrary scripts.

The affected endpoints correspond to various configurations within the system, including payment methods, pricing tiers, variants, serial number types, seasons, categories, and brands. Each of these entry points is identified with a specific CVE code, from CVE-2026-6082 to CVE-2026-6088, all with a base CVSS v4.0 score of 5.1 and classified under the CWE-79 code, which corresponds to Cross-Site Scripting vulnerabilities.

Technical Implications and Current Status of the Vulnerability

Exploitation of this vulnerability requires the attacker to have authenticated access to the system, allowing for the remote execution of arbitrary JavaScript code in the StockAgile environment. This could compromise session integrity and the security of the data displayed in the administration panel, potentially facilitating unauthorized actions within the application.

Currently, there is no official solution published by Novadigits Technologies to address these vulnerabilities. INCIBE has issued this early alert to inform users and administrators of the risks posed by this vulnerability and the need to stay alert for future updates or patches that may mitigate the issue.

Reviewed by
Published: 28/09/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.