Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] XchangeOn | Web & API | Jul2025

Date:

Aug 27, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the XchangeOn team for the collaborative engagement that enabled the execution of this Pentest.

Document

NamePentest and Security Analysis Report for XchangeOn
Audited ByAbdelfattah Ibrahim
Approved ByStephen Ajayi
Websitehttps://xchangeon.ae/→
Changelog04/08/2025 - Preliminary Report
Changelog27/08/2025 - Final Report
TagsPentest
Methodologyhttps://hackenio.cc/pentest_methodology→

Protect your dApp with insights like these.

Audit Summary

13Total Findings
13Resolved
0Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

System Overview

XchangeOn is a comprehensive cryptocurrency trading platform designed to provide seamless digital asset trading services primarily for the UAE market. The platform operates as a full-featured exchange offering spot trading capabilities across 100+ currencies and 30+ cryptocurrencies, including proprietary tokens like BFIC and BLove. The system features real-time order execution, advanced charting tools, portfolio management capabilities, and smart order routing to deliver institutional-quality trading experiences to retail users. XchangeOn incorporates a comprehensive KYC/verification system with multiple verification levels that determine trading limits and withdrawal capabilities, ensuring regulatory compliance while maintaining user accessibility. The platform supports instant funding through crypto wallets and various payment methods, quick withdrawals, and 24/7 customer support through ticketing and live chat systems. Operating under the legal framework of XchangeOn S.R.O, the exchange maintains strict compliance with anti-bribery policies, privacy regulations, and virtual asset listing standards while offering competitive fee structures and multi-channel customer engagement through web, mobile applications, and social media presence across major platforms.

Findings

F-2025-1201Staff Memebers ResetCode Exposure via Unprotected Internal GraphQL Query
Status
fixed
Severity

Critical
F-2025-1201IDOR Leading to Exposure of KYC and Internal User Information via Email
Status
fixed
Severity

High
F-2025-1201IDOR Leading to Full P2P User Profile Disclosure
Status
fixed
Severity

High
F-2025-1200Insecure JWT Signing Algorithm
Status
fixed
Severity

Medium
F-2025-1200GraphQL Circular-Query via Introspection Allowed
Status
fixed
Severity

Medium
F-2025-1200GraphQL Array-based Query Batching Enabled
Status
fixed
Severity

Medium
F-2025-1201HTML Injection in Emails via Nickname Field
Status
fixed
Severity

Low
F-2025-1201Client-Side Restriction Bypass
Status
fixed
Severity

Low
F-2025-1200GraphQL Field Suggestions Enabled
Status
fixed
Severity

Low
F-2025-1200GraphQL Introspection Query Enabled
Status
fixed
Severity

Low
Code
―
Title
Status
Severity
F-2025-1201Staff Memebers ResetCode Exposure via Unprotected Internal GraphQL Query
fixed

Critical
F-2025-1201IDOR Leading to Exposure of KYC and Internal User Information via Email
fixed

High
F-2025-1201IDOR Leading to Full P2P User Profile Disclosure
fixed

High
F-2025-1200Insecure JWT Signing Algorithm
fixed

Medium
F-2025-1200GraphQL Circular-Query via Introspection Allowed
fixed

Medium
F-2025-1200GraphQL Array-based Query Batching Enabled
fixed

Medium
F-2025-1201HTML Injection in Emails via Nickname Field
fixed

Low
F-2025-1201Client-Side Restriction Bypass
fixed

Low
F-2025-1200GraphQL Field Suggestions Enabled
fixed

Low
F-2025-1200GraphQL Introspection Query Enabled
fixed

Low
1-10 of 13 findings

Uncover findings like these to secure your project.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following:

Assets in Scope

Web Application - Web Application

Disclaimer