Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (CWE‑79)
Action: Apply Patch
AI Analysis

Impact

Cross‑Site Scripting vulnerability is present in the Repasat application. The 'nomCompetidor' parameter in the "/es/competitors/store" endpoint is not properly sanitized, allowing an attacker to inject and execute arbitrary scripts when a user views the content. Successful exploitation permits script execution within the victim’s browser context, which can be used to manipulate the page or perform client‑side attacks. The CVSS score of 4.8 indicates a moderate level of severity.

Affected Systems

Affected product is the Repasat application. All versions before the April 2026 patch '20260402' are vulnerable. No specific sub‑versions are listed, so any current release that has not applied the patch should be considered at risk.

Risk and Exploitability

CVSS 4.8 places the vulnerability in the moderate severity range; EPSS is not available, and the flaw is not listed in CISA KEV, indicating no known exploitation at the time of reporting. The likely attack vector is an HTTP request that supplies a crafted 'nomCompetidor' value, typically triggered by a user following a malicious link or submitting a manipulated form. This inference is based on the description that the parameter is affected and would be sent to the server via a standard request.

Generated by OpenCVE AI on October 2, 2026 at 13:19 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the April 2026 patch version ‘20260402’ released by Repasat to fix the XSS flaw.
  • Validate and escape all data supplied through the 'nomCompetidor' parameter before rendering it in HTML responses to prevent injection of executable scripts.
  • Implement a strict Content Security Policy that disallows inline script execution and limits loaded scripts to trusted origins to mitigate impact if the flaw persists.

Generated by OpenCVE AI on October 2, 2026 at 13:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T10:07:12.011Z

Reserved: 2026-07-06T10:46:38.360Z

Link: CVE-2026-59662

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:07.713

Modified: 2026-10-02T10:17:07.713

Link: CVE-2026-59662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:44:54Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')