CVE-2026-79419: Emxtecnologia Gestao X Business Suite
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.
Affected products
- Emxtecnologia Gestao X Business Suite: up to and including 8.4
Published 2026-09-04. Last modified 2026-09-17.