CVE-2025-55887
Last modified
CVE-2025-55887 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output encoding, an attacker can inject malicious JavaScript code that is executed in the context of a user s browser. This can lead to session hijacking, theft of cookies, and other malicious actions performed on behalf of the victim.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ard | Gec En Ligne | All versions |
References
- https://github.com/0xZeroSec/CVE-2025-55887Exploit, Third Party Advisory
- https://github.com/0xZeroSec/CVE-2025-55887Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-55887?
How severe is CVE-2025-55887?
How do I fix CVE-2025-55887?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-55853SoftVision webPDF before 10.0.2 is vulnerable to Server-Side…9.1
- CVE-2025-5586The WordPress Ajax Load More and Infinite Scroll plugin for …6.4
- CVE-2025-5587The Appzend theme for WordPress is vulnerable to Stored Cros…6.4
- CVE-2025-5588The Image Editor by Pixo plugin for WordPress is vulnerable …6.4
- CVE-2025-55885SQL Injection vulnerability in Alpes Recherche et Developpem…6.3
- CVE-2025-55886An Insecure Direct Object Reference (IDOR) vulnerability was…6.5
- CVE-2025-55888Cross-Site Scripting (XSS) vulnerability was discovered in t…7.3
- CVE-2025-5589The StreamWeasels Kick Integration plugin for WordPress is v…6.4
- CVE-2025-55893TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to comm…6.5
- CVE-2025-55895TOTOLINK A3300R V17.0.0cu.557_B20221024 and N200RE V9.3.5u.6…9.1
- CVE-2025-5590The Owl carousel responsive plugin for WordPress is vulnerab…8.8
- CVE-2025-55901TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to com…6.5
Are you affected by CVE-2025-55887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
