Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly.
This is fixed as of version 7.5.018
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15823 | Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018 |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://docs.rapid7.com/release-notes/appspider/20250516/ |
|
Thu, 11 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rapid7:appspider_pro:*:*:*:*:*:*:*:* |
Wed, 21 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 May 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2025-05-20T13:36:46.854Z
Reserved: 2025-05-19T10:06:45.924Z
Link: CVE-2025-4951
Updated: 2025-05-20T13:36:39.655Z
Status : Analyzed
Published: 2025-05-20T09:15:21.207
Modified: 2025-12-11T18:21:25.300
Link: CVE-2025-4951
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:16Z
EUVD