CVE-2026-79418: XSS
EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authenticated to Gestao X and able to submit user-controlled content through the Help Chat functionality. The injected JavaScript executes in the context of other authenticated users who view the affected content.
Which versions are affected?
Gestao X versions 8.4 and earlier are identified as affected.
What could an attacker achieve through successful exploitation?
Successful exploitation can execute arbitrary JavaScript in another authenticated user's browser. This may enable session hijacking, account takeover, or unauthorized actions performed using the victim's session.