CVE-2026-79419

NONE
CVSS v3
CVSS v2
0.16% EPSS (exploit probability)
CWE

Description

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references