PT-2026-29209 · Unknown · Anon Proxy Server
Rafael Pedrero
·
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2025-41355
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Anon Proxy Server version 0.104
Description
A Reflected Cross-Site Scripting (XSS) issue exists in Anon Proxy Server. This allows an attacker to execute JavaScript code in a victim’s browser through a malicious URL. This could lead to the theft of sensitive user data, such as session cookies, or actions performed on behalf of the user. The issue affects the
port and proxyPort parameters in the '/anon.php' endpoint.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anon Proxy Server