Cross-Site Scripting Vulnerability in Repasat Application by INCIBE
CVE-2026-59659
4.8MEDIUM
What is CVE-2026-59659?
The Repasat application contains a Cross-Site Scripting vulnerability that targets the 'nomZonaGeo' parameter in the endpoint '/es/geozones/update/149979'. Exploiting this vulnerability can enable attackers to manipulate unsuspecting users into executing arbitrary code within their browsers, thereby compromising user security and potentially exposing sensitive information.
Affected Version(s)
Repasat application 0
