Impact
A reflected Cross‑Site Scripting flaw exists in the Repasat application. The flaw is triggered by the \"nomTamano\" query parameter sent to the \/es\/companysizebills\/store endpoint, leading to the execution of injected JavaScript in a victim’s browser. Because the payload runs with the user’s privileges, an attacker could hijack sessions, steal credentials, or perform other malicious actions that appear to originate from the user. This weakness is classified as CWE‑79, an input validation flaw that allows arbitrary script injection.
Affected Systems
The vulnerability affects the Repasat application as released by Repasat. No specific product version is listed; however, the official patch that addresses the flaw is the April release labeled 20260402 and applies to all current installations of the application.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, with no exploit probability forecast available via EPSS and the vulnerability not present in CISA’s KEV catalog. Attackers can exploit the flaw by crafting a URL that includes a malicious payload in the \"nomTamano\" parameter and luring a user to visit that URL. Successful exploitation does not require prior authentication or elevated privileges, but the victim must have a browser that executes the injected script. Because the flaw is a traditional reflected XSS, the likelihood of exploitation depends on user interaction, but the impact on trusted browsers could be significant. The lack of EPSS data makes it difficult to quantify the current threat level, but the moderate CVSS score warrants timely mitigation.
OpenCVE Enrichment