Impact
A Cross‑Site Scripting flaw exists in the Repasat application, targeting the "nomTamano" parameter on the "/es/companysizemployees/update" endpoint. This weakness allows an attacker to embed malicious script that will run inside a victim’s web browser when the victim views a crafted page, potentially allowing the attacker to steal credentials, perform phishing, or hijack the user session.
Affected Systems
The vulnerability is present in the Repasat application. No specific version numbers are enumerated, but the vendor has released an April patch (20260402) that fixes the issue. All installations of Repasat must be confirmed as updated to this patch version. The patch resolves the underlying XSS flaw associated with the "nomTamano" input.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation to date. The likely attack vector requires a user to visit a maliciously crafted URL or otherwise interact with the vulnerable page. Once the XSS payload executes, the attacker could gain the victim’s in‑browser privileges, compromising confidentiality, integrity, and availability of the user session.
OpenCVE Enrichment