Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or administrators access the affected sections, the code executes in their browsers, enabling the theft of session cookies and account hijacking.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or administrators access the affected sections, the code executes in their browsers, enabling the theft of session cookies and account hijacking. | |
| Title | Stored Cross-Site Scripting (XSS) vulnerability in Stel Order | |
| First Time appeared |
Stel Order
Stel Order stel Order |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:stel_order:stel_order:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Stel Order
Stel Order stel Order |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-05-14T13:47:51.077Z
Reserved: 2026-04-08T12:41:41.410Z
Link: CVE-2026-5790
Updated: 2026-05-14T13:47:47.055Z
Status : Received
Published: 2026-05-14T13:16:21.173
Modified: 2026-05-14T13:16:21.173
Link: CVE-2026-5790
No data.