StockAgile API 和管理面板中存在存储型跨站脚本攻击(Stored XSS)漏洞。该漏洞存在于服务器端的 REST 接口 中,允许通过 'code'、'name' 以及其他文本字段注入并持久化恶意的 JavaScript 代码。输入的代码在未经正确过滤或验证的情况下,会被显示在已认证用户可以访问的 Web 面板中。攻击者可利用此漏洞,以已认证的远程攻击者身份执行任意 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Novadigits technologies | StockAgile | 0 ~ 25/09/2026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6082 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6083 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6084 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6085 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6088 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
| CVE-2026-6086 | 5.1 MEDIUM | Stored Cross-Site Scripting in StockAgile by Novadigits technologies |
No comments yet