---
id: CVE-2026-79419
title: >-
  A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia
  Gestao X Business Suite 8.4 and earlier
summary: >-
  A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia
  Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by
  insufficient validation and sanitization of the mensagem parameter in the
  /Configuracao…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: emxtecnologia
product: gestao_x_business_suite
affected:
  - gestao_x_business_suite <= 8.4
published: '2026-09-04'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T19:20:50.983'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79419'
references:
  - url: 'https://drive.google.com/file/d/1QVH1MRo3G4KqmBORkhXITzcYmO_BDjWc/view'
    label: cve@mitre.org
  - url: 'https://emxtecnologia.com.br/gestao-x-business-suite/'
    label: cve@mitre.org
  - url: 'https://drive.google.com/file/d/1QVH1MRo3G4KqmBORkhXITzcYmO_BDjWc/view'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00383
epssPercentile: 0.29607
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T16:20:25.159980Z'
ingestedAt: '2026-09-06T01:47:58.732Z'
---

## Overview

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.

## Affected

- `gestao_x_business_suite <= 8.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
