Junglewise Threat Intelligence

CVE-2026-5790: Stel Order stored XSS in FrontController

CVE-2026-5790 · Severity: info · CVSS 5.1 · Published 2026-05-14

Executive brief

Stel Order, a cloud-based business management platform, contains a security flaw that allows attackers to inject malicious scripts into the system. When an employee or administrator views the affected records, the script runs in their browser, potentially allowing the attacker to steal login sessions or take over accounts. This could lead to unauthorized access to sensitive business and employee data.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Stel Order v3.25.1 and earlier at the '/app/FrontController' endpoint. The vulnerability is caused by a lack of proper input sanitization of the 'legalName' and 'employeeID' parameters. An attacker can inject malicious JavaScript that is persistently stored in the application's database. When other users or administrators view the compromised data, the script executes in their browser context, enabling session cookie theft and account hijacking. As of the advisory date, no official patch or solution has been reported.

Affected products

  • Stel Order Stel Order 3.25.1 and earlier

Timeline

  • 2026-05-14: disclosed: Initial disclosure by INCIBE-CERT
  • 2026-05-14: advisory: NVD publication date

References

Related threats