Junglewise Threat Intelligence

CVE-2025-51628: Agenzia Impresa Eccobook IDOR in PdfHandler

CVE-2025-51628 · Severity: high · CVSS 7.5 · Published 2025-08-05

Technologies: Agenzia Impresa Eccobook. Vendors: Agenzia Impresa.

Executive brief

Agenzia Impresa Eccobook, a business management software, contains a security flaw in how it handles document requests. An unauthorized person can access and read sensitive PDF documents by simply guessing or cycling through document ID numbers in a web link. This could lead to the exposure of confidential business records or customer data without requiring any login credentials.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the PdfHandler component of Agenzia Impresa Eccobook v2.81.1 and below. The vulnerability is located in the 'PdfHandler.ashx' endpoint, specifically within the 'DocumentoId' parameter. Because this parameter uses predictable, incrementing integers and lacks proper authorization checks, an unauthenticated attacker can perform a brute-force attack on the ID values to retrieve and read any uploaded PDF document. This is a network-based attack that requires no prior authentication or user interaction.

Affected products

  • Agenzia Impresa Eccobook v2.81.1 and below

Timeline

  • 2025-08-05: advisory: NVD publication date

References

Related threats