CVE-2019-25403: Comodo Dome Firewall 2.7.0 Stored Cross-Site Scripting via admin_profiles
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input to the comment parameter. Attackers can inject JavaScript code through the adminprofiles endpoint that executes in the browsers of other users who view the affected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25403?
The severity of CVE-2019-25403 is classified as medium due to its ability to allow authenticated attackers to perform stored cross-site scripting attacks.
How do I fix CVE-2019-25403?
To fix CVE-2019-25403, ensure that you update Comodo Dome Firewall to the latest version that patches this vulnerability.
What type of attack does CVE-2019-25403 enable?
CVE-2019-25403 enables stored cross-site scripting attacks, which allow attackers to inject malicious scripts into web applications.
Who is affected by CVE-2019-25403?
CVE-2019-25403 affects users of Comodo Dome Firewall version 2.7.0 who enable comment functionalities.
Is there a workaround for CVE-2019-25403?
As a temporary workaround for CVE-2019-25403, restrict access to affected functionalities until an update can be applied.