CVE-2019-25409: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via routing
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the destination parameter. Attackers can send POST requests to the routing endpoint with script payloads in the destination parameter to execute arbitrary JavaScript in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25409?
CVE-2019-25409 is classified as a high severity reflected cross-site scripting vulnerability.
How do I fix CVE-2019-25409?
To fix CVE-2019-25409, users should update Comodo Dome Firewall to the latest version that addresses this vulnerability.
What impact does CVE-2019-25409 have on users?
CVE-2019-25409 allows attackers to inject malicious scripts, potentially leading to session hijacking or data theft.
Who is affected by CVE-2019-25409?
CVE-2019-25409 affects users of Comodo Dome Firewall version 2.7.0.
Can CVE-2019-25409 be exploited remotely?
Yes, CVE-2019-25409 can be exploited remotely by sending specially crafted POST requests.