PT-2026-29209 · Unknown · Anon Proxy Server

Rafael Pedrero

·

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2025-41355

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Anon Proxy Server version 0.104
Description A Reflected Cross-Site Scripting (XSS) issue exists in Anon Proxy Server. This allows an attacker to execute JavaScript code in a victim’s browser through a malicious URL. This could lead to the theft of sensitive user data, such as session cookies, or actions performed on behalf of the user. The issue affects the port and proxyPort parameters in the '/anon.php' endpoint.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-41355

Affected Products

Anon Proxy Server