CVE-2025-55887
MEDIUMARD GEC En Ligne - transactionID Cross-Site Scripting
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2025-55887. PoCs published by 0xZeroSec.
AI-analyzed exploit summary This repository contains a Proof of Concept (PoC) for CVE-2025-55887, demonstrating a Cross-Site Scripting (XSS) vulnerability in the meal reservation service ARD. The vulnerability is exploited via the transactionID GET parameter, allowing arbitrary JavaScript execution in the context of a user's browser.
Description
Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that is executed in the context of a user s browser. This can lead to session hijacking, theft of cookies, and other malicious actions performed on behalf of the victim.
Exploits (1)
This repository contains a Proof of Concept (PoC) for CVE-2025-55887, demonstrating a Cross-Site Scripting (XSS) vulnerability in the meal reservation service ARD. The vulnerability is exploited via the transactionID GET parameter, allowing arbitrary JavaScript execution in the context of a user's browser.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N