Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomMotivo” parameter is affected – endpoint “/es/lostmotives/store”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Cross‑Site Scripting in the Repasat application allows attackers to inject malicious scripts through the 'nomMotivo' parameter on the /es/lostmotives/store endpoint. Successful exploitation can cause a victim’s browser to execute arbitrary JavaScript, leading to credential theft, session hijacking, or phishing attacks. This vulnerability is classified as CWE‑79, a classic injection weakness where input is improperly validated before being reflected in the output.

Affected Systems

The vulnerability affects the Repasat application, all versions prior to the April 2026 patch 20260402. No specific legacy versions are listed; the patch release date indicates that any earlier build is potentially vulnerable. Administrators should verify if their deployment uses the legacy application and upgrade accordingly.

Risk and Exploitability

The CVSS score of 4.8 reflects moderate severity, and the lack of an EPSS score means no recent exploitation data is available. The vulnerability is not listed in the CISA KEV catalog. Attackers must lure a user to submit a crafted 'nomMotivo' value or to click a malicious link; therefore user interaction is required for exploitation. The impact is limited to the victim’s browser session, but can still compromise sensitive data or redirect to malicious sites.

Generated by OpenCVE AI on October 2, 2026 at 11:24 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the April 2026 patch version 20260402 to the Repasat application.
  • Validate and encode all user input in the 'nomMotivo' parameter before rendering it in HTTP responses.
  • Restrict or secure the /es/lostmotives/store endpoint, and consider implementing a Content‑Security Policy to mitigate XSS payloads.

Generated by OpenCVE AI on October 2, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomMotivo” parameter is affected – endpoint “/es/lostmotives/store”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T16:19:40.633Z

Reserved: 2026-07-06T10:46:38.360Z

Link: CVE-2026-59665

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:08.143

Modified: 2026-10-02T10:17:08.143

Link: CVE-2026-59665

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:44:48Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')