CVE-2019-25406: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via organization Parameter
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the organization parameter. Attackers can send POST requests to the korugan/cmclient endpoint with script payloads in the organization parameter to execute arbitrary JavaScript in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25406?
CVE-2019-25406 is rated as a high severity vulnerability due to its potential to allow attackers to execute scripts on the affected system.
How do I fix CVE-2019-25406?
To mitigate CVE-2019-25406, ensure that you upgrade to the latest version of Comodo Dome Firewall that addresses this reflected cross-site scripting vulnerability.
What software is affected by CVE-2019-25406?
CVE-2019-25406 affects Comodo Dome Firewall version 2.7.0.
What type of vulnerability is CVE-2019-25406?
CVE-2019-25406 is a reflected cross-site scripting (XSS) vulnerability.
What can an attacker do exploiting CVE-2019-25406?
An attacker exploiting CVE-2019-25406 can inject and execute malicious scripts on the client side by manipulating the organization parameter in POST requests.