Impact
Stored Cross‑Site Scripting (XSS) is present in the Help Chat feature of EMX Tecnologia Gestao X, allowing authenticated users to embed malicious JavaScript that is rendered in the browsers of other authenticated users. The injected code runs in the context of those users, potentially stealing session cookies, hijacking sessions, and allowing account takeover or other unauthorized actions. This attack can compromise the confidentiality, integrity, and availability of the application for every user who views the chat content.
Affected Systems
EMX Tecnologia Gestao X version 8.4 and lower are affected. No other vendors or products are listed in the advisory.
Risk and Exploitability
The vulnerability is exploitable only by users who can submit content to the Help Chat, which requires authentication. Because the payload is executed in the victim’s browser, the attack vector is client‑side. The EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The CVSS score of 8.7 reflects high severity, but the potential for session hijacking and account takeover gives it a significant impact for each affected user.
OpenCVE Enrichment