CVE-2025-55886
Severity CVSS v4.0:
Pending analysis
Type:
CWE-693
Protection Mechanism Failure
Publication date:
22/09/2025
Last modified:
17/11/2025
Description
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



