Impact
The Repasat application contains an improper input handling flaw that permits a cross‑site scripting (XSS) attack. By supplying a crafted value in the “nomTransportista” parameter on the /es/carriers/update endpoint, an attacker can embed malicious JavaScript that runs in the context of any user visiting the page. Exploitation grants the attacker the ability to execute arbitrary code within the user’s browser session, potentially allowing session hijacking, defacement, or credential theft.
Affected Systems
All deployments of the Repasat application that have not applied the April 2026 patch version ‘20260402’. No specific earlier versions are enumerated; any release prior to the patched build could be vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user to load the vulnerable endpoint with a maliciously crafted request, so social engineering or a malicious link may be needed. The flaw does not affect the server state directly but can compromise any user interacting with the page, making it a notable risk for users who have sensitive data or privileged accounts.
OpenCVE Enrichment