Junglewise Threat Intelligence

CVE-2025-55888: ARD GEC en ligne XSS in Ajax transaction manager

CVE-2025-55888 · Severity: high · CVSS 7.3 · Published 2025-09-22

Technologies: Ard Gec En Ligne. Vendors: Ard.

Executive brief

A security vulnerability has been identified in ARD's online transaction management system. Attackers can inject malicious scripts into the system's responses, which are then executed in the web browsers of legitimate users. This could allow unauthorized individuals to steal login sessions, capture sensitive cookies, or perform actions on behalf of the user without their knowledge.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Ajax transaction manager endpoint (tx_afereload_ajax_transactionmanager) of ARD GEC en ligne. The vulnerability is rooted in the improper sanitization and encoding of the 'accountName' field within Ajax responses. An attacker can intercept and modify these responses to include malicious JavaScript, which is subsequently executed by the victim's browser when the data is rendered. This flaw is reachable over the network without authentication and can result in session hijacking or cookie theft. A proof-of-concept has been identified in public repositories.

Affected products

  • ARD GEC en ligne -

Timeline

  • 2025-09-22: advisory: Initial disclosure by MITRE and CISA-ADP

References

Related threats