Impact
CVE‑2026‑59671 describes a cross‑site scripting weakness in the '/es/datatables/getemployeetypesdatatable' endpoint of the Repasat application. By crafting a request that returns malicious JavaScript, an attacker can cause it to execute inside any victim’s browser that loads the page. This compromise can lead to session hijacking, theft of sensitive data, or malicious defacement of web content.
Affected Systems
The flaw targets the Repasat application. Only deployments that have not applied the April patch version 20260402 are vulnerable; no specific earlier version ranges are listed. All users of Repasat that expose the affected endpoint are at risk.
Risk and Exploitability
The CVSS score of 4.8 characterizes the flaw as moderate. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the weakness remotely via the web when a user interacts with a page that triggers the vulnerable endpoint, allowing the injection of arbitrary client‑side code into the victim’s browser session.
OpenCVE Enrichment