Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field.
Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly.
This is fixed as of version 7.5.018
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://docs.rapid7.com/release-notes/appspider/20250516/ |
![]() ![]() |
History
Wed, 21 May 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 20 May 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018 | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: rapid7
Published: 2025-05-20T08:39:38.370Z
Updated: 2025-05-20T13:36:46.854Z
Reserved: 2025-05-19T10:06:45.924Z
Link: CVE-2025-4951

Updated: 2025-05-20T13:36:39.655Z

Status : Awaiting Analysis
Published: 2025-05-20T09:15:21.207
Modified: 2025-05-21T20:25:16.407
Link: CVE-2025-4951

No data.