CVE-2026-59662: Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Repasat applicationto a version that resolves this vulnerability.Fixed in 20260402
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker needs to supply a malicious value through the nomCompetidor parameter at the /es/competitors/store endpoint and trick a user into executing it in their browser. The CVSS vector indicates that low privileges are required and user interaction is required.
What is the likely impact if exploitation succeeds?
Successful exploitation can cause arbitrary code to execute in the victim's browser. The reported CVSS impacts indicate limited effects on confidentiality and integrity, with no reported availability impact.