Junglewise Threat Intelligence

CVE-2025-51629: Agenzia Impresa Eccobook Reflected XSS in PdfViewer

CVE-2025-51629 · Severity: high · CVSS 8.8 · Published 2025-08-07

Technologies: Agenzia Impresa Eccobook. Vendors: Agenzia Impresa.

Executive brief

Agenzia Impresa Eccobook is a business management platform. A security flaw in its PDF viewing component allows an attacker to execute malicious scripts in a user's browser if the user clicks on a specially crafted link. This could lead to unauthorized access to sensitive business data, session hijacking, or the performance of actions on behalf of an administrative user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the PdfViewer.aspx component of Agenzia Impresa Eccobook version 2.81.1 and earlier. The application fails to properly sanitize or validate several input parameters, including 'Temp', 'DocumentoId', 'CommittenteId', and 'Nome', before reflecting them in the web response. An unauthenticated remote attacker can exploit this by tricking a victim into clicking a malicious URL containing a crafted JavaScript payload (e.g., using SVG onload events). Successful exploitation allows the execution of arbitrary code in the context of the victim's browser session, potentially leading to the theft of session cookies or unauthorized administrative actions. A proof-of-concept has been disclosed by researchers.

Affected products

  • Agenzia Impresa Eccobook 2.81.1 and below

Timeline

  • 2025-08-07: advisory: CVE published by MITRE/NVD
  • 2025-08-07: disclosed: Technical details and PoC released by Capgemini Red Team

References

Related threats