Executive brief
Agenzia Impresa Eccobook, a business management platform, contains a security flaw in its document management component. An attacker with a standard, low-level user account can bypass security restrictions to perform administrative actions, such as uploading documents to restricted areas. This could lead to unauthorized data modification and a full takeover of administrative functions within the application.
Technical details
An improper access control vulnerability (CWE-284) exists in the CaricaVerbale endpoint of Agenzia Impresa Eccobook. While the front-end interface enforces read-only permissions for low-privileged users, the server-side component fails to adequately validate session permissions for document upload operations. An attacker can intercept and replay administrative requests (such as document uploads) using a low-privileged user's session cookies via a web proxy. This allows a user with minimal access to bypass UI restrictions and perform high-privileged actions, effectively escalating their privileges to Administrator.
Affected products
- Agenzia Impresa Eccobook 2.81.1 and below
Timeline
- 2025-08-05: advisory: Initial disclosure of CVE-2025-51627