Description
EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.
Published: 2026-09-04
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Client‑Side Script Execution
Action: Patch
AI Analysis

Impact

Stored Cross‑Site Scripting (XSS) is present in the Help Chat feature of EMX Tecnologia Gestao X, allowing authenticated users to embed malicious JavaScript that is rendered in the browsers of other authenticated users. The injected code runs in the context of those users, potentially stealing session cookies, hijacking sessions, and allowing account takeover or other unauthorized actions. This attack can compromise the confidentiality, integrity, and availability of the application for every user who views the chat content.

Affected Systems

EMX Tecnologia Gestao X version 8.4 and lower are affected. No other vendors or products are listed in the advisory.

Risk and Exploitability

The vulnerability is exploitable only by users who can submit content to the Help Chat, which requires authentication. Because the payload is executed in the victim’s browser, the attack vector is client‑side. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The CVSS score of 8.7 reflects high severity, but the potential for session hijacking and account takeover gives it a significant impact for each affected user.

Generated by OpenCVE AI on September 21, 2026 at 05:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official patch released by EMX Tecnologia for this vulnerability
  • Delete or neutralize any malicious messages already posted in the Help Chat
  • Disable the Help Chat feature or restrict it to trusted users only
  • Implement strict input validation and ensure that user‑supplied content is properly sanitized to prevent XSS (CWE-79)

Generated by OpenCVE AI on September 21, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Stored XSS in EMX Tecnologia Gestao X Help Chat

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:emxtecnologia:gestao_x_business_suite:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in EMX Tecnologia Gestao X Help Chat

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Emxtecnologia
Emxtecnologia gestao X Business Suite
Vendors & Products Emxtecnologia
Emxtecnologia gestao X Business Suite

Fri, 04 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in EMX Tecnologia Gestao X Help Chat
Weaknesses CWE-79

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.
References

Subscriptions

Emxtecnologia Gestao X Business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T18:50:00.984Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79418

cve-icon Vulnrichment

Updated: 2026-09-08T13:59:15.941Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:18:00.103

Modified: 2026-09-17T19:20:40.700

Link: CVE-2026-79418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')