Impact
A vulnerability was identified in Omega Solution's CoinEx Crypto version 2025 within the Ticket Attachment Upload component. The flaw allows an attacker to inject malicious script into the /user/ticket functionality, leading to cross‑site scripting (CWE‑79) and potentially code execution (CWE‑94). If exploited, the attacker could execute arbitrary JavaScript in the context of legitimate users, stealing session cookies or performing unauthorized actions on the application.
Affected Systems
Affected systems are the CoinEx Crypto web application developed by Omega Solution, specifically the ticket upload feature exposed through /user/ticket. No specific version range beyond 2025 is provided, and the product’s website is no longer available, suggesting the product may be retired or replaced.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate severity vulnerability. The EPSS score is not available, and the issue is not listed in CISA KEV, but publicly available proof‑of‑code has been released, confirming that remote exploitation is possible. Attackers can target the application from any network location with moderate difficulty, potentially compromising confidentiality, integrity, or availability of user sessions.
OpenCVE Enrichment