Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizebills/store”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Potential arbitrary code execution in victim’s browser
Action: Apply Patch
AI Analysis

Impact

A reflected Cross‑Site Scripting flaw exists in the Repasat application. The flaw is triggered by the \"nomTamano\" query parameter sent to the \/es\/companysizebills\/store endpoint, leading to the execution of injected JavaScript in a victim’s browser. Because the payload runs with the user’s privileges, an attacker could hijack sessions, steal credentials, or perform other malicious actions that appear to originate from the user. This weakness is classified as CWE‑79, an input validation flaw that allows arbitrary script injection.

Affected Systems

The vulnerability affects the Repasat application as released by Repasat. No specific product version is listed; however, the official patch that addresses the flaw is the April release labeled 20260402 and applies to all current installations of the application.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, with no exploit probability forecast available via EPSS and the vulnerability not present in CISA’s KEV catalog. Attackers can exploit the flaw by crafting a URL that includes a malicious payload in the \"nomTamano\" parameter and luring a user to visit that URL. Successful exploitation does not require prior authentication or elevated privileges, but the victim must have a browser that executes the injected script. Because the flaw is a traditional reflected XSS, the likelihood of exploitation depends on user interaction, but the impact on trusted browsers could be significant. The lack of EPSS data makes it difficult to quantify the current threat level, but the moderate CVSS score warrants timely mitigation.

Generated by OpenCVE AI on October 2, 2026 at 11:51 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Update the Repasat application to the April 2026 patch version 20260402, which resolves the reflected XSS in the \"nomTamano\" parameter.
  • Implement server‑side validation or whitelisting for the \"nomTamano\" input, ensuring that only permitted characters or values are accepted.
  • Configure a strict Content‑Security‑Policy header on all Repasat responses to block inline script execution and prevent injected JavaScript from running.

Generated by OpenCVE AI on October 2, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizebills/store”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T10:50:42.990Z

Reserved: 2026-07-06T10:46:38.360Z

Link: CVE-2026-59668

cve-icon Vulnrichment

Updated: 2026-10-02T10:50:35.513Z

cve-icon NVD

Status : Received

Published: 2026-10-02T11:17:34.797

Modified: 2026-10-02T11:17:34.797

Link: CVE-2026-59668

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:44:39Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')