Impact
The vulnerability is a Cross‑Site Scripting flaw in the Repasat application that allows an attacker to inject malicious script into the "nomListaValidacion" parameter of the "/es/validationslists/assignList/Employee/45659" endpoint. Successful exploitation can lead to arbitrary code execution within a victim’s browser, potentially compromising user data and session integrity.
Affected Systems
The flaw affects all versions of the Repasat application that have not yet applied the April 2026 patch "20260402". The vendor has confirmed that the patch addresses the XSS issue; any installations prior to this release are impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate impact, and no EPSS score is available, suggesting limited publicly known exploitation. The vulnerability is client‑side, requiring a user to visit a crafted URL or accept a malicious prompt, so exploitation potential depends on user interaction. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread active attacks at this time.
OpenCVE Enrichment