Impact
The vulnerability is a classic reflected cross‑site scripting flaw in the Repasat application. An attacker can supply a malicious value for the "nomGrupoEmpresarial" parameter on the "/es/corporategroups/update/246" endpoint. If the input is not properly sanitized or encoded, the attacker’s script will be executed in the victim’s browser, allowing the attacker to run arbitrary client‑side code, hijack the session or deface the interface. The impact is limited to the victim’s browser context and does not provide remote code execution on the server.
Affected Systems
The affected product is the Repasat application, as identified by the Repasat CNA. All releases prior to the April patch version 20260402 are vulnerable. The patch has been released by Repasat to address the cross‑site scripting flaw.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, which suggests a lower likelihood of widespread exploitation. The likely attack vector is a web‑based request requiring an end‑user to visit a crafted URL or click a malicious link that includes the vulnerable "nomGrupoEmpresarial" parameter. Exploitation depends on the user’s interaction with the application; there is no automated or remote trigger documented.
OpenCVE Enrichment