Impact
A cross‑site scripting flaw was discovered in the name parameter of the Repasat application’s "/es/attachmenttypes/update" endpoint. A crafted payload can be executed in the victim’s browser, allowing an attacker to run arbitrary JavaScript in the context of an authenticated user. This can lead to credential theft, session hijacking, or delivery of further malicious content.
Affected Systems
The flaw affects all installed instances of the Repasat application before the April 2026 patch series ‘20260402’. The vendor confirmed that the vulnerability is present in every release that predates the announced patch, with no specific client or server version exempted.
Risk and Exploitability
The CVSS score of 4.8 indicates a low‑to‑medium severity; the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog. The attack vector is web‑based, requiring the attacker to deliver a malicious link or form that a user opens and interacts with. The flaw permits arbitrary JavaScript execution in the victim’s browser, potentially allowing session hijacking, credential theft, or further malicious activity. Based on typical XSS risks, the impact could be serious if the victim is logged into the application.
OpenCVE Enrichment