CVE-2026-59668: Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizebills/store”.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Repasat applicationto a version that resolves this vulnerability.Fixed in 20260402
Event History
Frequently Asked Questions
What input and application route should be prioritized for testing and monitoring?
The affected input is the “nomTamano” parameter at the “/es/companysizebills/store” endpoint. Review whether this parameter is reflected or stored and whether submitted values are rendered without appropriate output encoding.
What does an attacker need to exploit this issue?
An attacker needs to cause a victim to execute malicious script in their browser through the affected parameter. The available information does not state whether authentication, specific user roles, or other preconditions are required.
What is the potential impact on a successful exploit?
Successful exploitation could trick a user into executing arbitrary code in the victim’s browser. The provided information does not specify impacts beyond browser-side code execution.