Executive brief
StockAgile is inventory and retail management software used by stores, e-commerce sites, and warehouses. A flaw in the API and management panel allows authenticated users to inject malicious JavaScript code through text fields that is then displayed to other users, potentially enabling account takeover or session hijacking of other administrators or staff members.
Technical details
Stored XSS vulnerability in multiple REST endpoints (/inventory/configuration/brands, /inventory/configuration/categories, and others) due to insufficient input validation and output encoding on text fields such as 'code' and 'name'. An authenticated attacker can inject persistent malicious JavaScript that executes in the context of other users' browser sessions when they view the affected pages. No patch is currently available.
Affected products
- Novadigits technologies StockAgile <UNKNOWN>
Timeline
- 2026-09-25: disclosed