{"id":"CVE-2026-59660","title":"Cross-Site Scripting vulnerability in the Repasat application","summary":"Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter …","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-79"],"vendor":"Repasat","product":"Repasat application","affected":["application < Abril patch \"20260402\""],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T10:17:07.417","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59660","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-repasat-application","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-02T10:15:55.898Z","slug":"CVE-2026-59660","body":"## Overview\n\nCross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTransportista” parameter is affected – endpoint “/es/carriers/update”.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}