Impact
A reflected Cross‑Site Scripting (XSS) flaw exists in the Repasat application. The vulnerability is triggered through the user‑supplied "nomZonaGeo" parameter on the /es/geozones/update/149979 endpoint. If successfully exploited, an attacker can provoke a victim’s browser to execute arbitrary JavaScript, enabling actions such as session hijacking, cookie theft, content injection, or phishing. The weakness is an example of CWE‑79, a client‑side code injection flaw.
Affected Systems
The flaw affects the Repasat application as distributed by the vendor Repasat. Current product releases before the April 2026 patch (version 20260402) are vulnerable; newer releases are presumed fixed.
Risk and Exploitability
The CVSS score of 4.8 places the issue in a moderate range, and no EPSS value is available, suggesting limited information on real‑world exploitation probability. The flaw is not listed in CISA’s KEV catalog. Exploitation requires a user to be tricked into visiting a crafted URL or interacting with a malicious form within the Repasat web app, making it an attack that depends on user interaction rather than remote code execution on the server side.
OpenCVE Enrichment