CVE-2025-41356
MEDIUMReflected Cross-Site Scripting in Anon Proxy Server
Title source: cnaDescription
Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'host' parameter in '/diagconnect.php' endpoint.
References (1)
Core 1
Scores
CVSS v3
6.1
EPSS
0.0019
EPSS Percentile
9.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
Anon Proxy Server/Anon Proxy Server
0.104
anonproxyserver/anon_proxy_server
0.104
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026