Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field.
Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly.
This is fixed as of version 7.5.018
            Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly.
This is fixed as of version 7.5.018
Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-15823 | Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018 | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://docs.rapid7.com/release-notes/appspider/20250516/ | 
                     | 
            
History
                    Wed, 21 May 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 20 May 2025 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018 | |
| Weaknesses | CWE-79 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2025-05-20T13:36:46.854Z
Reserved: 2025-05-19T10:06:45.924Z
Link: CVE-2025-4951
Updated: 2025-05-20T13:36:39.655Z
Status : Awaiting Analysis
Published: 2025-05-20T09:15:21.207
Modified: 2025-05-21T20:25:16.407
Link: CVE-2025-4951
No data.
                        OpenCVE Enrichment
                    Updated: 2025-06-24T09:44:16Z
 EUVD