← Back

CVE-2025-55888

nvd nist
Published: Sep 22, 2025Modified: Oct 14, 2025

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 3.9 / Impact: 3.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered, allowing script execution in the context of users browsers. This flaw could lead to session hijacking, cookie theft, and other malicious actions.

Affected (1)

Products: Ard: Gec En Ligne
1 product
Gec En Ligne
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (4)

Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
Broken Link

Timeline

No history available yet.