CVE-2025-55887

MEDIUM

ARD GEC En Ligne - transactionID Cross-Site Scripting

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-55887. PoCs published by 0xZeroSec.

AI-analyzed exploit summary This repository contains a Proof of Concept (PoC) for CVE-2025-55887, demonstrating a Cross-Site Scripting (XSS) vulnerability in the meal reservation service ARD. The vulnerability is exploited via the transactionID GET parameter, allowing arbitrary JavaScript execution in the context of a user's browser.

Description

Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that is executed in the context of a user s browser. This can lead to session hijacking, theft of cookies, and other malicious actions performed on behalf of the victim.

Exploits (1)

nomisec WORKING POC 3 stars
by 0xZeroSec · poc
https://github.com/0xZeroSec/CVE-2025-55887

This repository contains a Proof of Concept (PoC) for CVE-2025-55887, demonstrating a Cross-Site Scripting (XSS) vulnerability in the meal reservation service ARD. The vulnerability is exploited via the transactionID GET parameter, allowing arbitrary JavaScript execution in the context of a user's browser.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: ARD meal reservation service
No auth needed
Prerequisites: Access to the vulnerable ARD service URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Broken Link
http://alpes.com
Broken Link
http://ard.com
Exploit, Third Party Advisory
https://github.com/0xZeroSec/CVE-2025-55887

Scores

CVSS v3 6.1
EPSS 0.0043
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
ard/gec_en_ligne
Published Sep 22, 2025
Tracked Since Feb 18, 2026