Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Client‑side script execution via XSS
Action: Immediate Patch
AI Analysis

Impact

Cross‑Site Scripting when the user supplies a crafted 'nomOrigen' value to the '/es/origins/store' endpoint can execute arbitrary JavaScript in the victim’s browser, potentially compromising confidentiality and integrity of the user session. The flaw arises from deficient sanitization of user input, classified as CWE‑79.

Affected Systems

The Repasat application, any installation that has not applied the April 2026 patch code 20260402, remains susceptible. The vulnerability affects the endpoint handling the 'nomOrigen' parameter in the origin store functionality.

Risk and Exploitability

The CVSS score of 4.8 indicates medium severity. There is no EPSS data available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of active exploitation. The attack requires a user to visit a malicious link or form that submits the injected payload; thus the threat depends on user interaction.

Generated by OpenCVE AI on October 2, 2026 at 11:23 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the official April 2026 patch (code 20260402) to the Repasat application to resolve the underlying input‑validation flaw.
  • Validate and escape all content passed to the 'nomOrigen' field on both server‑side and client‑side to ensure no arbitrary script can be injected.
  • Deploy a Content Security Policy header that restricts script execution to trusted origins, mitigating the impact of any residual XSS.
  • Configure a web‑application firewall or an XSS filtering rule set to detect and block malicious scripts targeting the /es/origins/store endpoint.

Generated by OpenCVE AI on October 2, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T11:29:25.023Z

Reserved: 2026-07-06T10:46:38.360Z

Link: CVE-2026-59666

cve-icon Vulnrichment

Updated: 2026-10-02T11:29:20.252Z

cve-icon NVD

Status : Received

Published: 2026-10-02T11:17:34.503

Modified: 2026-10-02T12:17:20.720

Link: CVE-2026-59666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T11:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')