CVE-2026-59666: Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Repasat applicationto a version that resolves this vulnerability.Fixed in 20260402
Event History
Frequently Asked Questions
What conditions are required for exploitation?
The CVSS vector indicates network access, low privileges, and user interaction are required. An attacker would need to cause a user to interact with the malicious content for the browser-side code execution to occur.
What impact is indicated if exploitation succeeds?
The CVSS assessment indicates low-impact compromise of confidentiality and integrity, with no availability impact. The affected security scope is limited to the vulnerable application’s context.