Cross-Site Scripting Vulnerability in Repasat Application by Vendor
CVE-2026-59665

4.8MEDIUM

Key Information:

Vendor

Repasat

Vendor
CVE Published:
2 October 2026

What is CVE-2026-59665?

The Repasat application has a Cross-Site Scripting vulnerability that exposes users to the risk of arbitrary code execution in their browsers. The vulnerability affects the 'nomMotivo' parameter within the endpoint '/es/lostmotives/store'. Attackers can exploit this issue to inject malicious scripts, potentially leading to unauthorized actions being performed in the context of the user's session. It is crucial for users to be aware of this vulnerability and implement security measures to protect against possible exploitation.

Affected Version(s)

Repasat application 0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David Padilla Alvarado
.