Description
A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.
Published: 2026-09-13
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting allowing arbitrary JavaScript execution in the app’s context
Action: Apply Patch
AI Analysis

Impact

A stored cross‑site scripting flaw (CWE‑79) in the Repetico web backend lets an authenticated user submit malicious JavaScript into the text field of a multiple‑choice question. When the question is later displayed by the Android client, the payload runs in the app’s JavaScript context, giving the attacker permission to execute arbitrary scripts within the application.

Affected Systems

The vulnerability exists only in the Repetico web backend, version 1.9.7.31 for Android. No other vendors, product lines or versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium‑severity flaw, while the EPSS score of less than 1% suggests a low probability of current exploitation; the vulnerability is not in the CISA KEV catalog. Exploitation requires a remote authenticated user to upload a malicious question, after which any viewer of that question on the Android app will have the embedded script executed in the app’s context.

Generated by OpenCVE AI on September 15, 2026 at 18:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Repetico web backend to a patched release that resolves the XSS flaw.
  • Ensure that any input in the multiple‑choice question field is properly sanitized or encoded before rendering, preventing unsanitized data from being inserted into the DOM.
  • Deploy a Content Security Policy that disallows inline script execution and restricts script sources to trusted origins.

Generated by OpenCVE AI on September 15, 2026 at 18:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Repetico
Repetico web Backend
Vendors & Products Repetico
Repetico web Backend

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title XSS in Repetico Web Backend Allows Authenticated Users to Execute Arbitrary JavaScript

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title XSS in Repetico Web Backend Allows Authenticated Users to Execute Arbitrary JavaScript
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Repetico Web Backend
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:50:37.151Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63842

cve-icon Vulnrichment

Updated: 2026-09-14T15:50:32.426Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T00:16:56.040

Modified: 2026-09-22T20:00:03.713

Link: CVE-2025-63842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:36Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')