CVE-2019-25404: Comodo Dome Firewall 2.7.0 Stored Cross-Site Scripting via admins
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input through admin management parameters. Attackers can inject script payloads in the adminname, name, and surname parameters via POST requests to the /korugan/admins endpoint, which are stored and executed when administrators access the interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25404?
CVE-2019-25404 is classified as a medium-severity vulnerability due to its potential impact on authenticated admin accounts.
How do I fix CVE-2019-25404?
To mitigate CVE-2019-25404, update to the latest version of Comodo Dome Firewall where the vulnerability has been addressed.
Who is affected by CVE-2019-25404?
CVE-2019-25404 affects users of Comodo Dome Firewall version 2.7.0 who have admin access.
What type of vulnerability is CVE-2019-25404?
CVE-2019-25404 is a stored cross-site scripting (XSS) vulnerability that allows the injection of malicious scripts.
What can attackers do with CVE-2019-25404?
Attackers exploiting CVE-2019-25404 can execute malicious scripts in the context of an authenticated admin's session.