Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affected versions allow standard users to add custom configuration files. These files, which are loaded in alphabetical order, can override or change the settings of the original configuration files, creating a security vulnerability. This issue stems from improper directory access management.

This vulnerability was remediated in version 7.5.021 of the product.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 25 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 25 Sep 2025 15:00:00 +0000

Type Values Removed Values Added
Description Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in the application's configuration file loading mechanism, whereby an attacker can place files in directories belonging to other users or projects. Affected versions allow standard users to add custom configuration files. These files, which are loaded in alphabetical order, can override or change the settings of the original configuration files, creating a security vulnerability. This issue stems from improper directory access management. This vulnerability was remediated in version 7.5.021 of the product.
Title Rapid7 Appspider Broken Access Control Vulnerability
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2025-09-25T16:03:45.231Z

Reserved: 2025-04-16T00:09:11.312Z

Link: CVE-2025-36857

cve-icon Vulnrichment

Updated: 2025-09-25T16:03:30.714Z

cve-icon NVD

Status : Received

Published: 2025-09-25T15:16:11.060

Modified: 2025-09-25T15:16:11.060

Link: CVE-2025-36857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.