Executive brief
EMX Tecnologia Gestao X is an integrated business management platform used to centralize operations, automate workflows, and manage customer interactions across multiple channels. A stored cross-site scripting vulnerability in the Help Chat feature allows authenticated users to inject malicious JavaScript that executes in the browsers of other authenticated users, enabling session hijacking, account takeover, and unauthorized actions on the platform.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw caused by improper neutralization of user-controlled input in the Help Chat functionality. Authenticated attackers can inject arbitrary JavaScript code through chat messages that is stored server-side and executed in the context of other authenticated users' browsers when they view the chat. This allows attackers to steal session cookies, capture credentials, perform actions on behalf of victims, or pivot to other system functions. The vulnerability requires authentication but affects all users who access the Help Chat feature after the malicious message is posted.
Affected products
- EMX Tecnologia Gestao X <= 8.4
Timeline
- 2026-09-04: disclosed