Back

MEDIUM

Multiple vulnerabilities in the Repasat application

Published Oct 2, 2026

Description

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” parameter is affected – endpoint “/es/providedservices/store”.

Affected products

Remediation

Vendor solution

The vulnerabilities have been fixed in the April patch version ‘20260402’.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Oct 2, 2026
Updated Oct 2, 2026
Reserved Jul 6, 2026
CISA Vulnrichment
Updated Oct 2, 2026
NVD
Status Deferred
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a