Aller au contenu

Fiche vulnérabilité

CVE-2025-41355 : faille moyenne anonproxyserver anon proxy server (CVSS 6.1)

Description

Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'port' and 'proxyPort' parameters in '/anon.php' endpoint.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
31 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • anonproxyserver anon proxy server

Références

Rechercher une autre vulnérabilité dans la base CVE