Impact
A Cross‑Site Scripting flaw exists in the Repasat application’s "nomTipoCli" parameter, specifically at the endpoint '/es/clientypes/update/109441'. Successful exploitation would permit an attacker to embed malicious script that is executed in the victim’s browser, enabling the attacker to run arbitrary code under the context of the user’s session. The impact is confined to the client side, providing an attacker with the ability to steal credentials, deface content, or defraud users, but not directly compromising the server or the application’s internal data.
Affected Systems
This vulnerability affects the Repasat application before the release of the April 2026 patch version 20260402. All earlier product releases remain vulnerable; no additional version details are provided.
Risk and Exploitability
The CVSS base score of 4.8 classifies the issue as a medium‑severity vulnerability. With no EPSS information available, current data cannot quantify exploitation probability; however, the lack of its presence in the CISA KEV catalog suggests the threat does not have a known public exploit. The likely attack vector is remote, via a crafted HTTP request to the affected endpoint, and requires the victim to visit the application or trigger the request. The overall risk to a typical deployment is moderate, warranting timely remediation.
OpenCVE Enrichment