Un nuevo aviso de seguridad

Imported from official source

Advisory

Cybersecurity Classified by Officially

API y el panel de gestión de StockAgile.

INCIBE ha coordinado la publicación de 7 vulnerabilidades de severidades medias que afecta a la API y el panel de gestión de StockAgile, software para tiendas, ecommerce y almacenes. La vulnerabilidad ha sido descubierta por Miguel Jiménez Cámara.

A estas vulnerabilidades se les ha asignado el siguiente código, puntuación base CVSS v4.0, vector del CVSS y el tipo de vulnerabilidad CWE:

  • Desde CVE-2026-6082 hasta CVE-2026-6088: 5.1 | CVSS:4.0 /AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N | CWE-79
  • No hay solución reportada por el momento.

    Vulnerabilidad de tipo Cross-Site Scripting (XSS) almacenada en la API y el panel de administración de StockAgile. La vulnerabilidad se encuentra en el lado del servidor, en diferentes endpoints REST, y permite la inyección y la persistencia de código JavaScript malicioso a través de parámetros como ‘code’, ‘name’ y otros campos de texto. Los scripts introducidos no se filtran ni se validan correctamente antes de mostrarse en el panel web al que pueden acceder los usuarios autenticados. La explotación de estas vulnerabilidades podría permitir a un atacante remoto, previamente autenticado, ejecutar código JavaScript arbitrario. 

    La lista de parámetros e identificadores asignados es la siguiente:

  • CVE-2026-6082: endpoint '/inventory/configuration/payment-methods';
  • CVE-2026-6083: endpoint  '/inventory/configuration/pricing-tiers';
  • CVE-2026-6084: endpoint  '/inventory/configuration/variants';
  • CVE-2026-6085: endpoint  '/inventory/configuration/serial-number-types';
  • CVE-2026-6086: endpoint  '/inventory/configuration/seasons';
  • CVE-2026-6087: endpoint  '/inventory/configuration/categories';
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.incibe.es/node/666282

    Officially imported this from INCIBE’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    INCIBE — imported from official source
    Official source
    https://www.incibe.es/rss.xml RSS
    Imported
    September 25, 2026 09:30
    Versions
    1 recorded
    Identity
    666282 at https://www.incibe.es

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.