CVE-2025-11195
—CVSS 3.1
3.3 low
EPSS
<1%p0
Published
()
Modified
Description
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effective verification of the uniqueness of project names when editing them outside the application in affected versions. This vulnerability was remediated in version 7.5.021 of the product.
- Vendors
- rapid7
- Products
- appspider pro
- Weakness
- CWE-20, CWE-345
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.