Impact
Cross‑Site Scripting when the user supplies a crafted 'nomOrigen' value to the '/es/origins/store' endpoint can execute arbitrary JavaScript in the victim’s browser, potentially compromising confidentiality and integrity of the user session. The flaw arises from deficient sanitization of user input, classified as CWE‑79.
Affected Systems
The Repasat application, any installation that has not applied the April 2026 patch code 20260402, remains susceptible. The vulnerability affects the endpoint handling the 'nomOrigen' parameter in the origin store functionality.
Risk and Exploitability
The CVSS score of 4.8 indicates medium severity. There is no EPSS data available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. The attack requires a user to visit a malicious link or form that submits the injected payload; thus the threat depends on user interaction.
OpenCVE Enrichment