Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the "ScanName" field.
Despite the application preventing the inclusion of special characters within the "ScanName" field, this could be bypassed by modifying the configuration file directly.
This is fixed as of version 7.5.018
CVE ID: CVE-2025-4951
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.6
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vendor: Rapid7
Product: AppSpider Pro
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 3.03% (scored less or equal to compared to others)
EPSS Date: 2025-06-18 (when was this score calculated)