n/a vulnerability

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.

Published 4 Sep 2026Updated 17 Sep 20263 sources
CVSS 5.4

Source timeline

CVE record published by NVDView source ↗