{"id":"CVE-2026-79418","title":"EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality","summary":"EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers …","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-79"],"vendor":"emxtecnologia","product":"gestao_x_business_suite","affected":["gestao_x_business_suite <= 8.4"],"published":"2026-09-04","updated":"2026-09-17","sourceUpdated":"2026-09-17T19:20:40.700","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79418","references":[{"url":"https://drive.google.com/file/d/1mp-uS-tAthH9FAObfx1D3lOM7IIjRsmE/view?usp=sharing","label":"cve@mitre.org"},{"url":"https://emxtecnologia.com.br/gestao-x-business-suite/","label":"cve@mitre.org"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00264,"epssPercentile":0.18569,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-09-15T18:49:39.097451Z"},"ingestedAt":"2026-09-08T15:33:26.962Z","slug":"CVE-2026-79418","body":"## Overview\n\nEMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.\n\n## Affected\n\n- `gestao_x_business_suite <= 8.4`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":204464,"id":"CVE-2026-79418","ts":1789501413322,"field":"exploit_available","old":"false","new":"true"},{"seq":204463,"id":"CVE-2026-79418","ts":1789501413322,"field":"cvss","old":"5.4","new":"8.7"},{"seq":204462,"id":"CVE-2026-79418","ts":1789501413322,"field":"severity","old":"medium","new":"high"}]}