CVE-2025-55886
MEDIUMARD Payment History API - Insecure Direct Object Reference
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2025-55886. PoCs published by 0xZeroSec.
AI-analyzed exploit summary This repository contains a writeup describing an Insecure Direct Object Reference (IDOR) vulnerability in ARD GEC en Ligne. The flaw allows authenticated attackers to access other users' payment history by manipulating the `fe_uid` parameter in the payment history API endpoint.
Description
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.
Exploits (1)
This repository contains a writeup describing an Insecure Direct Object Reference (IDOR) vulnerability in ARD GEC en Ligne. The flaw allows authenticated attackers to access other users' payment history by manipulating the `fe_uid` parameter in the payment history API endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N