Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting enabling arbitrary code execution in a victim’s browser
Action: Patch immediately
AI Analysis

Impact

The Repasat application contains an improper input handling flaw that permits a cross‑site scripting (XSS) attack. By supplying a crafted value in the “nomTransportista” parameter on the /es/carriers/update endpoint, an attacker can embed malicious JavaScript that runs in the context of any user visiting the page. Exploitation grants the attacker the ability to execute arbitrary code within the user’s browser session, potentially allowing session hijacking, defacement, or credential theft.

Affected Systems

All deployments of the Repasat application that have not applied the April 2026 patch version ‘20260402’. No specific earlier versions are enumerated; any release prior to the patched build could be vulnerable.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user to load the vulnerable endpoint with a maliciously crafted request, so social engineering or a malicious link may be needed. The flaw does not affect the server state directly but can compromise any user interacting with the page, making it a notable risk for users who have sensitive data or privileged accounts.

Generated by OpenCVE AI on October 2, 2026 at 11:29 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Upgrade the Repasat application to the April 2026 patch version ‘20260402’ to eliminate the XSS vulnerability.
  • Validate and sanitize the incoming ‘nomTransportista’ value on the /es/carriers/update endpoint, or reject requests that contain potential script payloads.
  • Deploy or configure a web application firewall or the browser’s XSS protection mechanisms to detect and block reflected XSS attempts, and monitor application logs for suspicious activity.

Generated by OpenCVE AI on October 2, 2026 at 11:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T09:43:53.035Z

Reserved: 2026-07-06T10:46:38.360Z

Link: CVE-2026-59660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:07.417

Modified: 2026-10-02T10:17:07.417

Link: CVE-2026-59660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:45:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')