CNNVD-202509-3546 Information

CNNVD ID

CNNVD-202509-3546

CVE-2025-55888

  • CNNVD Published: 2025-09-22

Description (Chinese)

ARD GEC en Ligne是法国ARD公司的一个线上服务门户网站。 ARD GEC en Ligne存在安全漏洞,该漏洞源于Ajax事务管理器端点未对accountName字段进行适当清理或编码,可能导致跨站脚本攻击。

Description (English)

ARD GEC en Ligne is an online service portal for ARD, France. ARD GEC en Ligne has a security loophole, which stems from the fact that the Ajax Service Manager peer did not properly clean or encode the accountName field, which could lead to a cross-site script attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

ARD

Published

2025-09-22

Last Modified

2026-02-24

References

https://services.ard.fr/?eID=tx_afereload_ajax_transactionmanager https://github.com/0xZeroSec/CVE-2025-55888 http://ard.com http://alpes.com https://access.redhat.com/security/cve/cve-2025-55888

Share on: