Description
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerabilities have been fixed in the April patch version ‘20260402’.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 02 Oct 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomCompetidor” parameter is affected – endpoint “/es/competitors/store”. | |
| Title | Multiple vulnerabilities in the Repasat application | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-10-02T10:07:12.011Z
Reserved: 2026-07-06T10:46:38.360Z
Link: CVE-2026-59662
No data.
Status : Received
Published: 2026-10-02T10:17:07.713
Modified: 2026-10-02T10:17:07.713
Link: CVE-2026-59662
No data.
OpenCVE Enrichment
No data.
Weaknesses