CVE-2025-55888 is a Cross-Site Scripting (XSS) vulnerability found in the Ajax transaction manager endpoint of ARD gec_en_ligne. An attacker can inject malicious JavaScript into the accountName field of an intercepted Ajax response, which is then executed in the context of a user's browser due to improper sanitization. This flaw carries a CVSS score of 7.3 (HIGH) and could lead to session hijacking, cookie theft, and other malicious actions, with a FAUCET Risk Score of 71/100. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ard:gec_en_ligne:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.