cve/2025/CVE-2025-55886.md
2025-09-29 21:09:30 +02:00

841 B

CVE-2025-55886

Description

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the fe_uid parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

POC

Reference

No PoCs from references.

Github