EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored Cross‑Site Scripting Vulnerability in EMX Tecnologia Gestao X Help Chat |
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Emxtecnologia
Emxtecnologia gestao X Business Suite |
|
| Vendors & Products |
Emxtecnologia
Emxtecnologia gestao X Business Suite |
Fri, 04 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored Cross‑Site Scripting Vulnerability in EMX Tecnologia Gestao X Help Chat | |
| Weaknesses | CWE-79 |
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-09-04T00:00:00.000Z
Updated: 2026-09-08T14:05:32.755Z
Reserved: 2026-08-25T00:00:00.000Z
Link: CVE-2026-79418
Updated: 2026-09-08T13:59:15.941Z
Status : Deferred
Published: 2026-09-04T16:18:00.103
Modified: 2026-09-09T16:04:24.933
Link: CVE-2026-79418
No data.