Impact
Cross‑site scripting exists in the Repasat application via the 'nomCompetidor' parameter at the '/es/competitors/store' endpoint. An attacker can inject malicious script that runs in the victim’s browser when the user visits a crafted page, enabling arbitrary code execution, theft of session data, or defacement. The attack requires user interaction with the page containing the vulnerable parameter. This flaw can lead to loss of confidentiality and integrity for affected users.
Affected Systems
The Repasat application, controlled by the vendor Repasat, is affected. All releases prior to the April patch version '20260402' contain the vulnerability. No specific older version numbers are listed.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via a crafted HTTP request to the vulnerable endpoint, and exploitation typically requires user interaction with a page that includes the malicious 'nomCompetidor' value. Overall risk is moderate, with limited likelihood of widespread exploitation without social engineering.
OpenCVE Enrichment