CVE-2025-11195
Last modified
CVE-2025-11195 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effective verification of the uniqueness of project names when editing them outside the application in affected versions. EPSS estimates a 0.08% chance of exploitation in the next 30 days.
Description
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name directly in the configuration file to a name that already exists. This issue stems from a lack of effective verification of the uniqueness of project names when editing them outside the application in affected versions. This vulnerability was remediated in version 7.5.021 of the product.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Appspider Pro | < 7.5.021 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-11195?
How severe is CVE-2025-11195?
How do I fix CVE-2025-11195?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-11189The Kiwire Captive Portal contains a reflected cross-site sc…7.3
- CVE-2025-1119The Appointment Booking Calendar — Simply Schedule Appointme…7.3
- CVE-2025-11190The Kiwire Captive Portal contains an open redirection issue…5.4
- CVE-2025-11191The RealPress WordPress plugin before 1.1.0 registers the R…5.3
- CVE-2025-11192A vulnerability in Extreme Networks’ Fabric Engine (VOSS) be…8.6
- CVE-2025-11193A potential vulnerability was reported in some Lenovo Tablet…6.8
- CVE-2025-11196The External Login plugin for WordPress is vulnerable to sen…4.3
- CVE-2025-11197The Draft List plugin for WordPress is vulnerable to Stored …6.4
- CVE-2025-11198A Missing Authentication for Critical Function vulnerability…8.5
- CVE-2025-11200MLflow Weak Password Requirements Authentication Bypass Vuln…9.8
- CVE-2025-11201MLflow Tracking Server Model Creation Directory Traversal Re…9.8
- CVE-2025-11202win-cli-mcp-server resolveCommandPath Command Injection Remo…9.8
Are you affected by CVE-2025-11195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
