PT-2025-38758 · Ard · Ard

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-55888

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ARD (affected versions not specified)
Description A Cross-Site Scripting (XSS) issue exists in the Ajax transaction manager endpoint of ARD. An attacker can intercept the Ajax response and inject malicious JavaScript into the accountName field. The input is not properly sanitized or encoded when rendered, enabling script execution within the user's browser. This could result in session hijacking and cookie theft. The API endpoint involved is '/Ajax transaction manager'.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55888

Affected Products

Ard