Description
A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-04
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Mitigate
AI Analysis

Impact

A vulnerability was identified in Omega Solution's CoinEx Crypto version 2025 within the Ticket Attachment Upload component. The flaw allows an attacker to inject malicious script into the /user/ticket functionality, leading to cross‑site scripting (CWE‑79) and potentially code execution (CWE‑94). If exploited, the attacker could execute arbitrary JavaScript in the context of legitimate users, stealing session cookies or performing unauthorized actions on the application.

Affected Systems

Affected systems are the CoinEx Crypto web application developed by Omega Solution, specifically the ticket upload feature exposed through /user/ticket. No specific version range beyond 2025 is provided, and the product’s website is no longer available, suggesting the product may be retired or replaced.

Risk and Exploitability

The CVSS base score of 5.1 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in CISA KEV, but publicly available proof‑of‑code has been released, confirming that remote exploitation is possible. Attackers can target the application from any network location with moderate difficulty, potentially compromising confidentiality, integrity, or availability of user sessions.

Generated by OpenCVE AI on October 4, 2026 at 06:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Patch or upgrade the CoinEx Crypto application to a version where the Ticket Attachment Upload validation issue is fixed, if such an update exists from Omega Solution.
  • Sanitize all user‑supplied input in the ticket attachment upload process and encode output to prevent script execution.
  • Disable or restrict the ticket attachment upload feature for users who do not require it, limiting the attack surface.
  • Monitor the application for signs of cross‑site scripting attacks, such as unexpected script execution in user sessions, and maintain logging to detect potential compromise.

Generated by OpenCVE AI on October 4, 2026 at 06:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Title Omega Solution CoinEx Crypto Ticket Attachment Upload ticket cross site scripting
First Time appeared Omega Solution
Omega Solution coinex Crypto
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*
Vendors & Products Omega Solution
Omega Solution coinex Crypto
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Omega Solution Coinex Crypto
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T03:30:16.721Z

Reserved: 2026-10-03T09:43:05.562Z

Link: CVE-2026-105099

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T05:16:26.010

Modified: 2026-10-04T05:16:26.010

Link: CVE-2026-105099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T08:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')