CVE-2025-41355 PUBLISHED

Reflected Cross-Site Scripting on Anon Proxy Server

Assigner: INCIBE
Reserved: 16.04.2025 Published: 31.03.2026 Updated: 31.03.2026

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'port' and 'proxyPort' parameters in '/anon.php' endpoint.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Anon Proxy Server
Product Anon Proxy Server
Versions Default: unaffected
  • Version 0.104 is affected

Solutions

Update to the lastest versión of the software.

Credits

  • Rafael Pedrero finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE