Impact
Stored Cross‑Site Scripting (XSS) is present in the Help Chat feature of EMX Tecnologia Gestao X, allowing authenticated users to embed malicious JavaScript that is rendered in the browsers of other authenticated users. The injected code runs in the context of those users, potentially stealing session cookies, hijacking sessions, and allowing account takeover or other unauthorized actions. This attack can compromise the confidentiality, integrity, and availability of the application for every user who views the chat content.
Affected Systems
EMX Tecnologia Gestao X version 8.4 and lower are affected. No other vendors or products are listed in the advisory.
Risk and Exploitability
The vulnerability is exploitable only by users who can submit content to the Help Chat, which requires authentication. Because the payload is executed in the victim’s browser, the attack vector is local to the client side. EPSS data is not available, but the KEV status indicates it is not listed in the CISA KEV catalog, and the potential impact of session hijacking and account takeover suggests a high threat level. The CVSS score is not supplied, but the described capabilities warrant urgent attention.
OpenCVE Enrichment