Impact
Cross‑Site Scripting vulnerability is present in the Repasat application. The 'nomCompetidor' parameter in the "/es/competitors/store" endpoint is not properly sanitized, allowing an attacker to inject and execute arbitrary scripts when a user views the content. Successful exploitation permits script execution within the victim’s browser context, which can be used to manipulate the page or perform client‑side attacks. The CVSS score of 4.8 indicates a moderate level of severity.
Affected Systems
Affected product is the Repasat application. All versions before the April 2026 patch '20260402' are vulnerable. No specific sub‑versions are listed, so any current release that has not applied the patch should be considered at risk.
Risk and Exploitability
CVSS 4.8 places the vulnerability in the moderate severity range; EPSS is not available, and the flaw is not listed in CISA KEV, indicating no known exploitation at the time of reporting. The likely attack vector is an HTTP request that supplies a crafted 'nomCompetidor' value, typically triggered by a user following a malicious link or submitting a manipulated form. This inference is based on the description that the parameter is affected and would be sent to the server via a standard request.
OpenCVE Enrichment