medium · CVSS v3 3.5 · CVSS v4 5.1 · EPSS 0.00191
CVE-2026-105099
CVE-2026-105099 is a cross‑site scripting vulnerability in the Ticket Attachment Upload component of Omega Solution CoinEx Crypto 2025. The
Overview
CVE-2026-105099 is a cross‑site scripting vulnerability in the Ticket Attachment Upload component of Omega Solution CoinEx Crypto 2025. The flaw allows remote attackers to inject malicious scripts via the /user/ticket endpoint. It could lead to session hijacking or defacement of the web interface.
Description
A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
The vulnerability permits attackers to inject arbitrary JavaScript into the web interface, potentially compromising the confidentiality of user data, the integrity of the application, and the availability if the site is defaced. Defenders should be aware that any user interacting with the Ticket Attachment Upload feature could be exposed to malicious payloads. The primary impact is on the web application and its users.
Remediation
Disable or remove the Ticket Attachment Upload feature until a patch is available. If the product is no longer maintained, consider migrating to a supported platform. Monitor for any suspicious activity in the /user/ticket endpoint and block known malicious payloads via web application firewall rules.
Risk context
The CVSS v4 score of 5.1 and EPSS of 0.00191 indicate a moderate risk, but the public availability of the exploit and lack of vendor response suggest a low but present threat. Defenders should treat this as a medium‑severity issue and prioritize remediation accordingly.
Affected products
- Omega Solution CoinEx Crypto 2025
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 3.5
- CVSS v4
- 5.1
- EPSS
- 0.00191