CVE-2026-59659

Summary

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomZonaGeo” parameter is affected – endpoint “/es/geozones/update/149979”.

Affected Software

VendorProductVersion RangeStatus
RepasatRepasat application0 < Abril patch "20260402"affected

Weaknesses

  • CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

References