Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “name” parameter is affected – endpoint “/es/attachmenttypes/update/203336”
Published: 2026-10-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Browser-based code execution via XSS
Action: Patch
AI Analysis

Impact

A cross‑site scripting flaw was discovered in the name parameter of the Repasat application’s "/es/attachmenttypes/update" endpoint. A crafted payload can be executed in the victim’s browser, allowing an attacker to run arbitrary JavaScript in the context of an authenticated user. This can lead to credential theft, session hijacking, or delivery of further malicious content.

Affected Systems

The flaw affects all installed instances of the Repasat application before the April 2026 patch series ‘20260402’. The vendor confirmed that the vulnerability is present in every release that predates the announced patch, with no specific client or server version exempted.

Risk and Exploitability

The CVSS score of 4.8 indicates a low‑to‑medium severity; the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog. The attack vector is web‑based, requiring the attacker to deliver a malicious link or form that a user opens and interacts with. The flaw permits arbitrary JavaScript execution in the victim’s browser, potentially allowing session hijacking, credential theft, or further malicious activity. Based on typical XSS risks, the impact could be serious if the victim is logged into the application.

Generated by OpenCVE AI on October 2, 2026 at 11:30 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the Apr‑2026 Repasat patch ‘20260402’ to remove the XSS flaw
  • Add a strict Content Security Policy that blocks inline scripts and restricts script loading to trusted domains to mitigate any remaining XSS risk during the patch transition
  • Validate and encode the ‘name’ request parameter, or disable the /es/attachmenttypes/update endpoint if it is no longer needed

Generated by OpenCVE AI on October 2, 2026 at 11:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “name” parameter is affected – endpoint “/es/attachmenttypes/update/203336”
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T08:40:52.853Z

Reserved: 2026-07-06T10:46:42.095Z

Link: CVE-2026-59669

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T09:16:44.223

Modified: 2026-10-02T09:16:44.223

Link: CVE-2026-59669

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:45:39Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')