Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTipoCli” parameter is affected – endpoint “/es/clientypes/update/109441”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side code execution via XSS
Action: Apply Patch
AI Analysis

Impact

A Cross‑Site Scripting flaw exists in the Repasat application’s "nomTipoCli" parameter, specifically at the endpoint '/es/clientypes/update/109441'. Successful exploitation would permit an attacker to embed malicious script that is executed in the victim’s browser, enabling the attacker to run arbitrary code under the context of the user’s session. The impact is confined to the client side, providing an attacker with the ability to steal credentials, deface content, or defraud users, but not directly compromising the server or the application’s internal data.

Affected Systems

This vulnerability affects the Repasat application before the release of the April 2026 patch version 20260402. All earlier product releases remain vulnerable; no additional version details are provided.

Risk and Exploitability

The CVSS base score of 4.8 classifies the issue as a medium‑severity vulnerability. With no EPSS information available, current data cannot quantify exploitation probability; however, the lack of its presence in the CISA KEV catalog suggests the threat does not have a known public exploit. The likely attack vector is remote, via a crafted HTTP request to the affected endpoint, and requires the victim to visit the application or trigger the request. The overall risk to a typical deployment is moderate, warranting timely remediation.

Generated by OpenCVE AI on October 2, 2026 at 10:24 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the vendor‑issued April 2026 patch version 20260402 to the Repasat application
  • Upgrade to the most recent Repasat release if the patch is unavailable
  • Implement input validation or output encoding for the "nomTipoCli" parameter to mitigate leftover XSS risk

Generated by OpenCVE AI on October 2, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTipoCli” parameter is affected – endpoint “/es/clientypes/update/109441”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T16:58:19.540Z

Reserved: 2026-07-06T10:46:42.095Z

Link: CVE-2026-59673

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:08.427

Modified: 2026-10-02T10:17:08.427

Link: CVE-2026-59673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:45:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')