Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server
v0.104. This vulnerability allows an attacker to execute JavaScript code
in the victim's browser by sending him/her a malicious URL. This
vulnerability can be exploited to steal sensitive user data, such as
session cookies, or to perform actions on behalf of the user. It affects
'port' and 'proxyPort' parameters in '/anon.php' endpoint.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-anon-proxy-server | Third Party Advisory |
Configurations
History
07 Apr 2026, 15:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-anon-proxy-server - Third Party Advisory | |
| CPE | cpe:2.3:a:anonproxyserver:anon_proxy_server:0.104:*:*:*:*:*:*:* | |
| First Time |
Anonproxyserver anon Proxy Server
Anonproxyserver |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| Summary |
|
31 Mar 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 09:16
Updated : 2026-04-07 15:32
NVD link : CVE-2025-41355
Mitre link : CVE-2025-41355
CVE.ORG link : CVE-2025-41355
JSON object : View
Products Affected
anonproxyserver
- anon_proxy_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
