Junglewise Threat Intelligence

CVE-2025-51627: Agenzia Impresa Eccobook privilege escalation in CaricaVerbale

CVE-2025-51627 · Severity: medium · CVSS 6.5 · Published 2025-08-05

Technologies: Agenzia Impresa Eccobook. Vendors: Agenzia Impresa.

Executive brief

Agenzia Impresa Eccobook, a business management platform, contains a security flaw in its document management component. An attacker with a standard, low-level user account can bypass security restrictions to perform administrative actions, such as uploading documents to restricted areas. This could lead to unauthorized data modification and a full takeover of administrative functions within the application.

Technical details

An improper access control vulnerability (CWE-284) exists in the CaricaVerbale endpoint of Agenzia Impresa Eccobook. While the front-end interface enforces read-only permissions for low-privileged users, the server-side component fails to adequately validate session permissions for document upload operations. An attacker can intercept and replay administrative requests (such as document uploads) using a low-privileged user's session cookies via a web proxy. This allows a user with minimal access to bypass UI restrictions and perform high-privileged actions, effectively escalating their privileges to Administrator.

Affected products

  • Agenzia Impresa Eccobook 2.81.1 and below

Timeline

  • 2025-08-05: advisory: Initial disclosure of CVE-2025-51627

References

Related threats