Description
Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.
It affects 'host' parameter in '/diagdns.php' endpoint.
It affects 'host' parameter in '/diagdns.php' endpoint.
No analysis available yet.
Remediation
Vendor Solution
Update the product to the lastest version.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 31 Mar 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'host' parameter in '/diagdns.php' endpoint. | |
| Title | Reflected Cross-Site Scripting on Anon Proxy Server | |
| First Time appeared |
Anon Proxy Server
Anon Proxy Server anon Proxy Server |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:anon_proxy_server:anon_proxy_server:0.104:*:*:*:*:*:*:* | |
| Vendors & Products |
Anon Proxy Server
Anon Proxy Server anon Proxy Server |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-31T09:19:37.864Z
Reserved: 2025-04-16T09:57:04.870Z
Link: CVE-2025-41357
No data.
Status : Received
Published: 2026-03-31T09:16:22.520
Modified: 2026-03-31T09:16:22.520
Link: CVE-2025-41357
No data.
OpenCVE Enrichment
No data.
Weaknesses