Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.
Published: 2026-10-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side code execution (cross‑site scripting)
Action: Apply Patch
AI Analysis

Impact

Cross‑site scripting exists in the Repasat application via the 'nomCompetidor' parameter at the '/es/competitors/store' endpoint. An attacker can inject malicious script that runs in the victim’s browser when the user visits a crafted page, enabling arbitrary code execution, theft of session data, or defacement. The attack requires user interaction with the page containing the vulnerable parameter. This flaw can lead to loss of confidentiality and integrity for affected users.

Affected Systems

The Repasat application, controlled by the vendor Repasat, is affected. All releases prior to the April patch version '20260402' contain the vulnerability. No specific older version numbers are listed.

Risk and Exploitability

The CVSS score is 4.8, indicating moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via a crafted HTTP request to the vulnerable endpoint, and exploitation typically requires user interaction with a page that includes the malicious 'nomCompetidor' value. Overall risk is moderate, with limited likelihood of widespread exploitation without social engineering.

Generated by OpenCVE AI on October 2, 2026 at 11:38 UTC.

Remediation

Vendor Solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.


OpenCVE Recommended Actions

  • Apply the April 2026 patch '20260402' to update the Repasat application.
  • Ensure the 'nomCompetidor' parameter output is properly escaped or encoded before rendering to prevent script execution.
  • Implement a Content Security Policy that limits script sources and blocks inline scripts to reduce the impact of any residual XSS.

Generated by OpenCVE AI on October 2, 2026 at 11:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Repasat
Repasat repasat Application
Vendors & Products Repasat
Repasat repasat Application

Fri, 02 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.
Title Multiple vulnerabilities in the Repasat application
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Repasat Repasat Application
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-10-02T09:51:31.849Z

Reserved: 2026-09-22T12:55:11.003Z

Link: CVE-2026-95662

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T10:17:09.937

Modified: 2026-10-02T10:17:09.937

Link: CVE-2026-95662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')