Description

Editions of Rapid7 AppSpider Pro before versionĀ 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of versionĀ 7.5.018

INFO

Published Date :

2025-05-20T08:39:38.370Z

Last Modified :

2025-05-20T13:36:46.854Z

Source :

rapid7
AFFECTED PRODUCTS

The following products are affected by CVE-2025-4951 vulnerability.

Vendors Products
Rapid7
  • Appspider Pro
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-4951.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact