Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to...
Vulnerability Description
Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly. This is fixed as of version 7.5.018
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4951
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Maksymilian Kubiak [Afine Team]
More from Rapid7
View All →Affected Vendor
Rapid7
View all reports →