CVE-2026-59667: Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizemployees/update”.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Repasat applicationto a version that resolves this vulnerability.Fixed in 20260402
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates low privileges are required and user interaction is required. An attacker would need access sufficient to submit the affected parameter, then convince a victim to interact with the malicious content.
Which part of the application should be prioritized for investigation?
Prioritize the /es/companysizemployees/update endpoint and its nomTamano parameter. Review whether values supplied through this parameter are reflected or otherwise rendered in users’ browsers without safe output handling.
What is the likely impact if exploitation succeeds?
Successful exploitation can cause arbitrary code to execute in the victim’s browser. The CVSS assessment identifies low impact to confidentiality and integrity, with no availability impact.