CVE-2026-59671: Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The endpoint “/es/datatables/getemployeetypesdatatable” is affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Repasat applicationto a version that resolves this vulnerability.Fixed in 20260402
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates low attacker privileges are required. Exploitation also requires user interaction, meaning the attacker must cause a victim to interact with malicious content that triggers code execution in the browser.
Which part of the application should be investigated?
The affected endpoint is /es/datatables/getemployeetypesdatatable. Review this endpoint’s handling and rendering of attacker-controlled input for cross-site scripting exposure.
What is the likely impact if exploitation succeeds?
An attacker could trick a user into executing arbitrary code in that user’s browser. The CVSS vector rates confidentiality and integrity impact as low and does not identify an availability impact.