CVE-2025-4951
Estado: AnalizadaMedia (4.6)—
Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field. Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly.
This is fixed as of version 7.5.018
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 4.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-4951",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-4951",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-20T13:34:10.824220Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@rapid7.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.6,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 1.5
}
]
},
"affected": [
{
"source": "cve@rapid7.com",
"affectedData": [
{
"vendor": "Rapid7",
"product": "AppSpider Pro",
"versions": [
{
"status": "affected",
"version": "Below 7.5.018"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-20T09:15:21.207",
"references": [
{
"url": "https://docs.rapid7.com/release-notes/appspider/20250516/",
"tags": [
"Release Notes"
],
"source": "cve@rapid7.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@rapid7.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the \"ScanName\" field.\nDespite the application preventing the inclusion of special characters within the \"ScanName\" field, this could be bypassed by modifying the configuration file directly.\n\nThis is fixed as of version 7.5.018"
},
{
"lang": "es",
"value": "Las ediciones de Rapid7 AppSpider Pro anteriores a la versión 7.5.018 son afectados por una vulnerabilidad de cross-site scripting almacenado en el campo \"ScanName\". Aunque la aplicación impide la inclusión de caracteres especiales en el campo \"ScanName\", esto se puede evitar modificando directamente el archivo de configuración. Esto se ha corregido a partir de la versión 7.5.018."
}
],
"lastModified": "2026-06-17T09:34:22.797",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rapid7:appspider_pro:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA39B4A4-2099-42B9-8F2D-98FB17B0A7F6",
"versionEndExcluding": "7.5.018"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@rapid7.com"
}