PT-2026-29211 · Unknown · Anon Proxy Server
Rafael Pedrero
·
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2025-41357
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Anon Proxy Server version 0.104
Description
A Reflected Cross-Site Scripting (XSS) vulnerability exists that allows an attacker to execute JavaScript code in a victim's browser by sending a malicious URL. This can be used to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. The vulnerability affects the
host parameter in the '/diagdns.php' API endpoint.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anon Proxy Server