CVE-2025-55886

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.
Configurations

No configuration.

History

17 Nov 2025, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5
CWE CWE-693

28 Oct 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

22 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 18:15

Updated : 2025-11-17 19:16


NVD link : CVE-2025-55886

Mitre link : CVE-2025-55886

CVE.ORG link : CVE-2025-55886


JSON object : View

Products Affected

No product.

CWE
CWE-693

Protection Mechanism Failure