Description
Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects
'host' parameter in '/diagconnect.php'
endpoint.
'host' parameter in '/diagconnect.php'
endpoint.
No analysis available yet.
Remediation
Vendor Solution
Update the producto to the lastest version.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 31 Mar 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'host' parameter in '/diagconnect.php' endpoint. | |
| Title | Reflected Cross-Site Scripting in Anon Proxy Server | |
| First Time appeared |
Anon Proxy Server
Anon Proxy Server anon Proxy Server |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:anon_proxy_server:anon_proxy_server:0.104:*:*:*:*:*:*:* | |
| Vendors & Products |
Anon Proxy Server
Anon Proxy Server anon Proxy Server |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-31T09:19:12.779Z
Reserved: 2025-04-16T09:57:04.870Z
Link: CVE-2025-41356
No data.
Status : Received
Published: 2026-03-31T09:16:22.347
Modified: 2026-03-31T09:16:22.347
Link: CVE-2025-41356
No data.
OpenCVE Enrichment
No data.
Weaknesses