CVE-2025-51629 Information

Description

A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Temp parameter.

Reference

http://agenzia.com http://eccobook.com https://github.com/CapgeminiCisRedTeam/Disclosure/blob/main/CVE%20PoC/CVE-2025-51629%20%7C%20Eccobook.md

CNNVD-202508-702 (Published: 2025-08-07)

Share on: