CVE-2025-55886

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.
Configurations

No configuration.

History

17 Nov 2025, 19:16

Type Values Removed Values Added
CWE CWE-693
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5

Information

Published : 2025-09-22 18:15

Updated : 2025-11-17 19:16


NVD link : CVE-2025-55886

Mitre link : CVE-2025-55886

CVE.ORG link : CVE-2025-55886


JSON object : View

Products Affected

No product.

CWE
CWE-693

Protection Mechanism Failure