Executive brief
Agenzia Impresa Eccobook, a business management software, contains a security flaw in how it handles document requests. An unauthorized person can access and read sensitive PDF documents by simply guessing or cycling through document ID numbers in a web link. This could lead to the exposure of confidential business records or customer data without requiring any login credentials.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the PdfHandler component of Agenzia Impresa Eccobook v2.81.1 and below. The vulnerability is located in the 'PdfHandler.ashx' endpoint, specifically within the 'DocumentoId' parameter. Because this parameter uses predictable, incrementing integers and lacks proper authorization checks, an unauthenticated attacker can perform a brute-force attack on the ID values to retrieve and read any uploaded PDF document. This is a network-based attack that requires no prior authentication or user interaction.
Affected products
- Agenzia Impresa Eccobook v2.81.1 and below
Timeline
- 2025-08-05: advisory: NVD publication date