CVE-2026-105099
Executive Summary
A cross‑site scripting (XSS) flaw exists in the Ticket Attachment Upload component of Omega Solution CoinEx Crypto 2025, allowing remote attackers to inject malicious scripts via the /user/ticket file. The vulnerability is publicly exploitable, yet the product appears retired and the vendor has not responded to disclosure. No KEV listing yet.
Authoritative CVE Metadata - CVSS Base Score: 3.5 (LOW) - Published: 2026-10-04T05:16:26.010 - Last Modified: 2026-10-04T05:16:26.010
Original Description: A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
"Study the past, if you would divine the future."
— Confucius