v0.104. This vulnerability allows an attacker to execute JavaScript code
in the victim's browser by sending him/her a malicious URL. This
vulnerability can be exploited to steal sensitive user data, such as
session cookies, or to perform actions on behalf of the user. It affects
'port' and 'proxyPort' parameters in '/anon.php' endpoint.
No advisories yet.
Solution
Update to the lastest versión of the software.
Workaround
No workaround given by the vendor.
Tue, 31 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'port' and 'proxyPort' parameters in '/anon.php' endpoint. | |
| Title | Reflected Cross-Site Scripting on Anon Proxy Server | |
| First Time appeared |
Anon Proxy Server
Anon Proxy Server anon Proxy Server |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:anon_proxy_server:anon_proxy_server:0.104:*:*:*:*:*:*:* | |
| Vendors & Products |
Anon Proxy Server
Anon Proxy Server anon Proxy Server |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-31T18:04:32.025Z
Reserved: 2025-04-16T09:57:04.869Z
Link: CVE-2025-41355
Updated: 2026-03-31T15:02:50.941Z
Status : Received
Published: 2026-03-31T09:16:22.137
Modified: 2026-03-31T09:16:22.137
Link: CVE-2025-41355
No data.
OpenCVE Enrichment
No data.