Home

Description

Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or administrators access the affected sections, the code executes in their browsers, enabling the theft of session cookies and account hijacking.

PUBLISHED Reserved 2026-04-08 | Published 2026-05-14 | Updated 2026-05-14 | Assigner INCIBE




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

Product status

Default status
unknown

Any version
affected

Credits

David Padilla Alvarado finder

References

www.incibe.es/...s/aviso/multiple-vulnerabilities-stel-order

cve.org (CVE-2026-5790)

nvd.nist.gov (CVE-2026-5790)

Download JSON