CVE-2019-25407: Comodo Dome Firewall 2.7.0 Cross-Site Scripting via backupschedule
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the backup schedule interface. Attackers can send POST requests to the backupschedule endpoint with JavaScript code in the BACKUPRCPTTO parameter to execute arbitrary scripts in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25407?
CVE-2019-25407 is classified as a medium severity vulnerability due to its ability to execute JavaScript via reflected cross-site scripting.
How do I fix CVE-2019-25407?
To fix CVE-2019-25407, you should update to the latest version of Comodo Dome Firewall that addresses the reflected cross-site scripting vulnerability.
What type of vulnerability is CVE-2019-25407?
CVE-2019-25407 is a reflected cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2019-25407?
Users of Comodo Dome Firewall version 2.7.0 are affected by CVE-2019-25407.
Can CVE-2019-25407 be exploited remotely?
Yes, CVE-2019-25407 can be exploited remotely by sending crafted POST requests to the backup schedule interface.