CVE-2026-79418
—Stored XSS in EMX Tecnologia Gestao X Help Chat Through Version 8.4
EMX Tecnologia Gestao X versions 8.4 and earlier contain a Stored Cross-Site Scripting (CWE-79) vulnerability in the product's Help Chat feature, caused by improper neutralization of user-controlled input during page generation. An authenticated attacker can inject malicious JavaScript into chat content, which then executes in the browsers of other authenticated users who view the chat, enabling session hijacking, account takeover, and unauthorized actions on their behalf. Any organization running Gestao X 8.4 or older with the Help Chat feature in use by multiple users is affected. The flaw carries a high CVSS 3.1 score of 8.7 due to its cross-scope impact on confidentiality and integrity, but exploitation currently appears unlikely: EPSS is only 0.2% (6th percentile), the issue is not in the CISA KEV catalog, and no public proof-of-concept exists.
What to do: Upgrade Gestao X to the latest vendor release, since all versions up to and including 8.4 are vulnerable, and confirm with EMX Tecnologia which build contains the fix. As interim mitigations, escape or sanitize user input rendered in the Help Chat, apply a Content-Security-Policy that restricts inline script execution, and review chat histories for injected scripts or suspicious links. Check logs and chat records for signs of prior injection attempts and rotate sessions of users who may have viewed malicious chat messages.
| EMX Tecnologia Gestao X | <= 8.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.