Impact
This vulnerability allows a malformed "nomDelegacion" parameter to be sent to the /es/delegations/store endpoint, injecting JavaScript into a victim’s browser. Successful exploitation could execute arbitrary code within the context of the user’s session, enabling session hijacking, defacement, or the delivery of phishing content. The impact is confined to the victim’s client environment, affecting confidentiality and integrity of the user session.
Affected Systems
The Repasat application is affected; no specific version numbers are listed. Only the /es/delegations/store endpoint and its "nomDelegacion" parameter are mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate risk. EPSS is unavailable, so the likelihood of exploitation cannot be quantified. The vulnerability is not in CISA KEV. The likely attack vector is remote, where an attacker crafts a request to the vulnerable endpoint and relies on a victim to visit the resulting page to trigger the script.
OpenCVE Enrichment