gec_en_ligne vulnerabilities
CVEs whose affected-version data names the gec_en_ligne package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-55887Medium· 6.1PoCCross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD
Cross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID GET parameter on the transaction confirmation page. Due to improper input validation and output en…
CVE-2025-55888High· 7.3PoCCross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD
Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. This input is not properly s…
CVE-2025-55885Medium· 6.3PoCSQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php
SQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate privileges via the GET parameters in index.php