Cross-Site Scripting Vulnerability in Repasat Application by Incibe
CVE-2026-95662
4.8MEDIUM
What is CVE-2026-95662?
The Repasat application has a vulnerability that enables cross-site scripting (XSS), specifically through the 'nomCompetidor' parameter on the '/es/competitors/store' endpoint. This flaw can be exploited by attackers to inject malicious scripts into the web pages visited by users, which could lead to unauthorized actions and data exposure in the victim’s browser. It is critical for users and developers of the Repasat application to take necessary precautions to mitigate this risk.
Affected Version(s)
Repasat application 0
