Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” parameter is affected – endpoint “/es/providedservices/store”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting enabling arbitrary code execution in a user’s browser
Action: Patch
AI Analysis

Impact

The vulnerability is a reflected XSS flaw in the "nomServicioPrestado" parameter of the Repasat application’s "/es/providedservices/store" endpoint. When the parameter is not properly encoded, an attacker can craft a URL that, once visited by a user, causes the victim’s browser to execute attacker‑supplied JavaScript. This can lead to session hijacking, data theft or other malicious actions performed as the authenticated user.

Affected Systems

Repasat application versions prior to the April patch 20260402 are impacted. The vulnerability is reported to exist in the current build running the "nomServicioPrestado" endpoint of the provided services module.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, with the attack requiring a user to click a malicious link or be tricked into visiting a tainted URL. EPSS data is not available, showing no publicly known exploitation statistics, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the ability for arbitrary script execution in a victim’s browser poses a serious risk to confidentiality and integrity if exploited in a social‑engineering scenario.

Generated by OpenCVE AI on October 2, 2026 at 11:52 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the April patch 20260402 to the Repasat application.
  • Implement server‑side validation and HTML‑encoding for the "nomServicioPrestado" parameter to mitigate reflected XSS.
  • Configure a strict Content Security Policy that blocks inline scripts to reduce the impact of any remaining XSS flaws.

Generated by OpenCVE AI on October 2, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” parameter is affected – endpoint “/es/providedservices/store”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T10:02:54.695Z

Reserved: 2026-07-06T10:46:38.360Z

Link: CVE-2026-59664

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:07.997

Modified: 2026-10-02T10:17:07.997

Link: CVE-2026-59664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:44:57Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')