VYPR
Medium severity6.5NVD Advisory· Published Sep 22, 2025· Updated Apr 15, 2026

CVE-2025-55886

CVE-2025-55886

Description

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the fe_uid parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.