CVE-2025-63842: XSS
A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.
Affected Software
Event History
Frequently Asked Questions
What access and interaction are required to exploit this issue?
An attacker must be authenticated to the web backend and must provide crafted input in a multiple-choice question text field. Exploitation also requires user interaction, as reflected by the UI:R vector.
What is the potential impact if exploitation succeeds?
The attacker can execute arbitrary JavaScript in the Repetico app's context. The available impact is limited confidentiality and integrity impact, with no availability impact indicated.
Which component and input should be prioritized for review?
Prioritize the web backend used by Repetico app for Android version 1.9.7.31, specifically handling and rendering of text entered into multiple-choice question fields.