SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79419

MEDIUM · CVSS 6.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A reflected cross-site scripting (XSS) vulnerability in EMX Tecnologia Gestao X Business Suite 8.4 and earlier allows unauthenticated attackers to inject and execute arbitrary JavaScript code via the insufficiently validated "mensagem" parameter in the /Configuracao/Imagens.aspx endpoint. This could lead to session hijacking, data theft, or other malicious actions affecting users' browsers. Organizations using this software should prioritize remediation to protect their users from potential exploitation.

CVE
CVE-2026-79419
Severity
MEDIUM
CVSS
6.1
EPSS
0.19%
Java

Original NVD Description

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.