CVE-2026-59672: Multiple vulnerabilities in the Repasat application
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomGrupoEmpresarial” parameter is affected – endpoint "/es/corporategroups/update/246”.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Repasat applicationto a version that resolves this vulnerability.Fixed in 20260402
Event History
Frequently Asked Questions
What access and interaction are required to exploit this issue?
The CVSS vector indicates that an attacker needs low privileges and that user interaction is required. The attacker would need to cause a victim to execute malicious browser-side code, such as by persuading them to use a crafted request or page involving the affected parameter.
Which input and endpoint should be reviewed during triage?
Review handling of the nomGrupoEmpresarial parameter at the /es/corporategroups/update/246 endpoint. Check whether values submitted to this parameter are reflected or rendered in browser-accessible content without appropriate output handling.
What is the likely impact if exploitation succeeds?
Successful exploitation can cause arbitrary code to run in the victim's browser. The CVSS assessment indicates low impact to confidentiality and integrity, with no availability impact.