Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomListaValidacion” parameter is affected – endpoint “/es/validationslists/assignList/Employee/45659”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side Remote Code Execution
Action: Patch
AI Analysis

Impact

The vulnerability is a Cross‑Site Scripting flaw in the Repasat application that allows an attacker to inject malicious script into the "nomListaValidacion" parameter of the "/es/validationslists/assignList/Employee/45659" endpoint. Successful exploitation can lead to arbitrary code execution within a victim’s browser, potentially compromising user data and session integrity.

Affected Systems

The flaw affects all versions of the Repasat application that have not yet applied the April 2026 patch "20260402". The vendor has confirmed that the patch addresses the XSS issue; any installations prior to this release are impacted.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate impact, and no EPSS score is available, suggesting limited publicly known exploitation. The vulnerability is client‑side, requiring a user to visit a crafted URL or accept a malicious prompt, so exploitation potential depends on user interaction. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread active attacks at this time.

Generated by OpenCVE AI on October 2, 2026 at 10:27 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Install the April 2026 patch version ‘20260402’ for the Repasat application.
  • Validate and encode the value of the "nomListaValidacion" parameter and any other user‑supplied input before rendering it to the browser.
  • Restrict or disable access to the vulnerable "assignList" endpoint for untrusted users, limiting the opportunity for exploitation.

Generated by OpenCVE AI on October 2, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomListaValidacion” parameter is affected – endpoint “/es/validationslists/assignList/Employee/45659”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T09:01:59.053Z

Reserved: 2026-07-06T10:46:42.095Z

Link: CVE-2026-59670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T09:16:44.390

Modified: 2026-10-02T09:16:44.390

Link: CVE-2026-59670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:45:33Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')