CVE-2026-5790
Stored Cross-Site Scripting (XSS) vulnerability in Stel Order
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper input sanitization allows an attacker to inject malicious code that is persistently stored in the database. When other users or administrators access the affected sections, the code executes in their browsers, enabling the theft of session cookies and account hijacking.
| CWE | CWE-79 |
| Vendor | stel order |
| Product | stel order |
| Published | May 14, 2026 |
| Last Updated | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for stel order stel order
Be the first to know when new unknown vulnerabilities affecting stel order stel order are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Stel Order / Stel Order
0 ≤ 3.25.1
References
Credits
David Padilla Alvarado