Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizemployees/update”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting that can execute arbitrary code in a victim’s browser
Action: Apply Patch
AI Analysis

Impact

A Cross‑Site Scripting flaw exists in the Repasat application, targeting the "nomTamano" parameter on the "/es/companysizemployees/update" endpoint. This weakness allows an attacker to embed malicious script that will run inside a victim’s web browser when the victim views a crafted page, potentially allowing the attacker to steal credentials, perform phishing, or hijack the user session.

Affected Systems

The vulnerability is present in the Repasat application. No specific version numbers are enumerated, but the vendor has released an April patch (20260402) that fixes the issue. All installations of Repasat must be confirmed as updated to this patch version. The patch resolves the underlying XSS flaw associated with the "nomTamano" input.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation to date. The likely attack vector requires a user to visit a maliciously crafted URL or otherwise interact with the vulnerable page. Once the XSS payload executes, the attacker could gain the victim’s in‑browser privileges, compromising confidentiality, integrity, and availability of the user session.

Generated by OpenCVE AI on October 2, 2026 at 11:22 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the April 20260402 patch for the Repasat application
  • Validate the "nomTamano" input to accept only numeric values and escape all output before rendering
  • Implement a Content Security Policy or use a trusted XSS‑filtering library to mitigate script execution

Generated by OpenCVE AI on October 2, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizemployees/update”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T10:55:28.067Z

Reserved: 2026-07-06T10:46:38.360Z

Link: CVE-2026-59667

cve-icon Vulnrichment

Updated: 2026-10-02T10:55:04.980Z

cve-icon NVD

Status : Received

Published: 2026-10-02T11:17:34.633

Modified: 2026-10-02T11:17:34.633

Link: CVE-2026-59667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:44:43Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')