---
id: CVE-2025-55888
title: >-
  Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax
  transaction manager endpoint of ARD
summary: >-
  Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax
  transaction manager endpoint of ARD. An attacker can intercept the Ajax
  response and inject malicious JavaScript into the accountName field. This
  input is not properly s…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-79
vendor: ard
product: gec_en_ligne
affected:
  - gec_en_ligne
published: '2025-09-22'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-55888'
references:
  - url: 'https://github.com/0xZeroSec/CVE-2025-55888'
    label: cve@mitre.org
  - url: 'https://services.ard.fr/?eID=tx_afereload_ajax_transactionmanager'
    label: cve@mitre.org
tags:
  - nvd
  - exploit-available
epss: 0.00441
epssPercentile: 0.35656
ingestedAt: '2026-07-06T16:44:34.262Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/0xZeroSec/CVE-2025-55888'
  checkedAt: '2026-09-26T09:05:34.073Z'
exploitAvailable: true
---

## Overview

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly sanitized or encoded when rendered, allowing script execution in the context of users browsers. This flaw could lead to session hijacking, cookie theft, and other malicious actions.

## Affected

- `gec_en_ligne`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
