Multiple vulnerabilities in the Repasat application
Repasat application.
INCIBE has coordinated the publication of 15 medium-severity vulnerabilities affecting the Repasat application, a business management software programme that enables all business operations to be consolidated onto a single platform. The vulnerabilities were discovered by David Padilla Alvarado.
These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector and CWE vulnerability type for each vulnerability:
- from CVE-2026-59669 to CVE-2026-59683: 4.8 | CVSS:4.0 AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N | CWE-79.
The vulnerabilities have been fixed in the April patch version ‘20260402’.
Cross-Site Scripting vulnerabilities in the Repasat application. Successful exploitation of these vulnerabilities could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The list of parameters and endpoints is as follows:
- CVE-2026-59659: “nomZonaGeo” parameter – endpoint "/es/geozones/update/149979".
- CVE-2026-59660: "nomTransportista" parameter – endpoint "/es/carriers/update".
- CVE-2026-59661: "nomRuta" parameter – endpoint "/es/routes/update/693".
- CVE-2026-59662: "nomCompetidor" parameter – endpoint "/es/competitors/store".
- CVE-2026-59663: "nomDelegacion" parameter – endpoint "/es/delegations/store".
- CVE-2026-59664: "nomServicioPrestado" parameter – endpoint "/es/providedservices/store".
- CVE-2026-59665: "nomMotivo" parameter – endpoint "/es/lostmotives/store".
- CVE-2026-59666: "nomOrigen" parameter – endpoint "/es/origins/store".
- CVE-2026-59667: "nomTamano" parameter – endpoint "/es/companysizemployees/update".
- CVE-2026-59668: “nomTamano” parameter – endpoint “/es/companysizebills/store”.
- CVE-2026-59669: “name” parameter – endpoint “/es/attachmenttypes/update/203336”.
- CVE-2026-59670: “nomListaValidacion” parameter – endpoint "/es/validationslists/assignList/Employee/45659".
- CVE-2026-59671: endpoint “/es/datatables/getemployeetypesdatatable”.
- CVE-2026-59672: “nomGrupoEmpresarial” parameter – endpoint "/es/corporategroups/update/246".
- CVE-2026-59673: “nomTipoCli” parameter – endpoint “/es/clientypes/update/109441”.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-59659 | Medio | No | REPASAT |
| CVE-2026-59660 | Medio | No | REPASAT |
| CVE-2026-59661 | Medio | No | REPASAT |
| CVE-2026-59662 | Medio | No | REPASAT |
| CVE-2026-59663 | Medio | No | REPASAT |
| CVE-2026-59664 | Medio | No | REPASAT |
| CVE-2026-59665 | Medio | No | REPASAT |
| CVE-2026-59666 | Medio | No | REPASAT |
| CVE-2026-59667 | Medio | No | REPASAT |
| CVE-2026-59668 | Medio | No | REPASAT |
| CVE-2026-59669 | Medio | No | REPASAT |
| CVE-2026-59670 | Medio | No | REPASAT |
| CVE-2026-59671 | Medio | No | REPASAT |
| CVE-2026-59672 | Medio | No | REPASAT |
| CVE-2026-59673 | Medio | No | REPASAT |


