Impact
Cross‑Site Scripting in the Repasat application allows attackers to inject malicious scripts through the 'nomMotivo' parameter on the /es/lostmotives/store endpoint. Successful exploitation can cause a victim’s browser to execute arbitrary JavaScript, leading to credential theft, session hijacking, or phishing attacks. This vulnerability is classified as CWE‑79, a classic injection weakness where input is improperly validated before being reflected in the output.
Affected Systems
The vulnerability affects the Repasat application, all versions prior to the April 2026 patch 20260402. No specific legacy versions are listed; the patch release date indicates that any earlier build is potentially vulnerable. Administrators should verify if their deployment uses the legacy application and upgrade accordingly.
Risk and Exploitability
The CVSS score of 4.8 reflects moderate severity, and the lack of an EPSS score means no recent exploitation data is available. The vulnerability is not listed in the CISA KEV catalog. Attackers must lure a user to submit a crafted 'nomMotivo' value or to click a malicious link; therefore user interaction is required for exploitation. The impact is limited to the victim’s browser session, but can still compromise sensitive data or redirect to malicious sites.
OpenCVE Enrichment