在 StockAgile API 和管理面板中存在存储型跨站脚本(XSS)漏洞。该漏洞出现在服务器端的 REST 端点 中,攻击者可以通过 、 以及其他文本字段等参数注入并持久化存储恶意 JavaScript 代码。系统未能对这些输入的脚本进行正确的过滤或验证,便将其直接展示在允许已认证用户访问的 Web 管理面板上。利用此漏洞,远程且已经通过身份验证的攻击者可能执行任意 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Novadigits technologies | StockAgile | 0 ~ 25/09/2026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6082 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6084 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6087 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6085 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6088 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6086 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
No comments yet