CVE-2026-59661: Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomRuta” parameter is affected – endpoint “/es/routes/update/693”.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Repasat applicationto a version that resolves this vulnerability.Fixed in 20260402
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs privileges (PR:L) and must convince a user to interact with the crafted content (UI:A). Exploitation occurs through the “nomRuta” parameter at the “/es/routes/update/693” endpoint.
What is the likely impact if exploitation succeeds?
A successful attack can cause arbitrary code to execute in the victim’s browser. The CVSS vector indicates low impact to confidentiality and integrity, with no availability impact.