CVE-2026-79419: XSS
A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an unauthenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of EMX Tecnologia Gestao X Business Suite 8.4 and earlier are exposed if they visit a crafted request targeting the /Configuracao/Imagens.aspx endpoint. An attacker does not need to authenticate to supply the malicious mensagem parameter.
What does an attacker need to exploit it?
The attacker needs to craft a URL or request containing JavaScript in the mensagem parameter and cause a victim to open it. The injected code executes in the victim's browser in the application's context.