Description
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effective verification of the uniqueness of project names when editing them outside the application in affected versions. This vulnerability was remediated in version 7.5.021 of the product.
INFO
Published Date :
2025-09-30T18:12:50.204Z
Last Modified :
2025-09-30T20:33:45.909Z
Source :
rapid7
AFFECTED PRODUCTS
The following products are affected by CVE-2025-11195 vulnerability.
| Vendors | Products |
|---|---|
| Rapid7 |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-11195.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact