Impact
The vulnerability is a reflected XSS flaw in the "nomServicioPrestado" parameter of the Repasat application’s "/es/providedservices/store" endpoint. When the parameter is not properly encoded, an attacker can craft a URL that, once visited by a user, causes the victim’s browser to execute attacker‑supplied JavaScript. This can lead to session hijacking, data theft or other malicious actions performed as the authenticated user.
Affected Systems
Repasat application versions prior to the April patch 20260402 are impacted. The vulnerability is reported to exist in the current build running the "nomServicioPrestado" endpoint of the provided services module.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, with the attack requiring a user to click a malicious link or be tricked into visiting a tainted URL. EPSS data is not available, showing no publicly known exploitation statistics, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the ability for arbitrary script execution in a victim’s browser poses a serious risk to confidentiality and integrity if exploited in a social‑engineering scenario.
OpenCVE Enrichment