在 Omega Solution CoinEx Crypto 2025 中发现了一个弱点。受此漏洞影响的是组件“票证附件上传”中 /user/ticket 文件的未知功能。这种操纵会导致跨站脚本(XSS)漏洞。攻击可以远程执行。该漏洞的利用方式已被公开,可能被用于攻击。该产品的官方网站已不再存在,可能该产品已被停用和/或被替换。厂商在披露之前已被联系,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Omega Solution | CoinEx Crypto | 2025 |
cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105096 | 6.3 MEDIUM | Omega Solution CoinEx Crypto Customer Profile API customer authorization |
| CVE-2026-105097 | 4.3 MEDIUM | Omega Solution CoinEx Crypto Customer Information API customer-currency authorization |
| CVE-2026-105098 | 4.3 MEDIUM | Omega Solution CoinEx Crypto Support Ticket API customer information disclosure |
No comments yet