CVE-2025-41357
EUVD-2025-20914131.03.2026, 09:16
Reflected Cross-Site Scripting (XSS) vulnerability in Anon Proxy Server v0.104. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending him/her a malicious URL. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. It affects 'host' parameter in '/diagdns.php' endpoint.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| anonproxyserver | anon_proxy_server | 0.104 |
𝑥
= Vulnerable software versions