Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/0xzerosec/cve-2025-55886
ReconnaissanceVulnerability AnalysisInformation GatheringWeb SecurityPenetration Testing
GitHub0xzerosec/cve-2025-55886

CVE-2025-55886

Advisory documenting an authenticated IDOR vulnerability in ARD's payment history API, allowing unauthorized access to other users' payment records through the fe_uid parameter.

View Repository
311 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-55886

Description

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the fe_uid parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

Affected Component

root@kitploit:~
https://services.ard.fr/?eID=tx_afereload_records&_dc=1743696277812&fe_uid={USERID]&startTimestamp=1741017877&endTimestamp=1743782677&mobile=1&page=1&start=0&limit=100

Affected Product Code Base

ARD GEC en Ligne - Not versioned - Patched on 2025-04-23

Reseachers

  • raphckrman
  • tryon-dev
Download Tool