cvedb.io
CVE-2025-11195
LOW · CVSS 3.3
EPSS exploitation probability: 0%
Published 2025-09-30T18:15:49.090 · Last modified 2026-06-17T08:29:50.177

Summary

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effective verification of the uniqueness of project names when editing them outside the application in affected versions. This vulnerability was remediated in version 7.5.021 of the product.

Affected products

rapid7 — appspider_pro

Does this affect you?

Add your gear to cvedb and we'll alert you only when rapid7 ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.