Rapid7 AppSpider Pro Project Name Validation Vulnerability

Vulnerability

A project name validation vulnerability exists in Rapid7 AppSpider Pro versions prior to 7.5.021. This vulnerability allows an attacker to modify the project name in the configuration file to duplicate an existing name. The issue arises from inadequate validation of project name uniqueness when names are edited outside the application.

Impact

Exploitation of this vulnerability could lead to project name conflicts, potentially causing confusion or errors in project management within the application.

Remediation

Users can upgrade to Rapid7 AppSpider Pro version 7.5.021 or later to address this vulnerability.

Added: Sep 30, 2025, 6:23 PM
Updated: Sep 30, 2025, 6:23 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
0.6
exploitability
4.9
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.