Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Simone Aiello

Researcher fromCapgeminiCisRedTeam
#16525of 53,633
16.3Total CVSS
Vulnerabilities · 2
High
2
PT-2025-32293
8.8
2025-08-07
Unknown · Agenzia Impresa Eccobook · CVE-2025-51629
**Name of the Vulnerable Software and Affected Versions** Agenzia Impresa Eccobook version 2.81.1 **Description** A cross-site scripting (XSS) vulnerability exists in the PdfViewer component. This allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the `Temp` parameter. **Recommendations** As a temporary workaround, consider disabling the PdfViewer component until a patch is available.
PT-2025-31948
7.5
2025-08-05
Unknown · Agenzia Impresa Eccobook · CVE-2025-51628
**Name of the Vulnerable Software and Affected Versions** Agenzia Impresa Eccobook versions prior to 2.81.2 **Description** An Insecure Direct Object Reference (IDOR) vulnerability exists in the PdfHandler component. This allows unauthenticated attackers to read confidential documents. The vulnerability is triggered through the `DocumentoId` parameter. **Recommendations** Update Agenzia Impresa Eccobook to a version prior to 2.81.2.