CVE-2019-25411: Comodo Dome Firewall 2.7.0 Cross-Site Scripting via DHCP
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the GATEWAYGREEN parameter. Attackers can send POST requests to the DHCP configuration endpoint with script payloads to execute arbitrary JavaScript in administrator browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25411?
CVE-2019-25411 is classified as a high severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2019-25411?
To fix CVE-2019-25411, update to the latest version of Comodo Dome Firewall that addresses this vulnerability.
What attack vectors are associated with CVE-2019-25411?
CVE-2019-25411 is exploited through POST requests that manipulate the GATEWAY_GREEN parameter on the DHCP configuration endpoint.
Who is affected by CVE-2019-25411?
Users of Comodo Dome Firewall version 2.7.0 are affected by CVE-2019-25411, specifically those enabling DHCP configuration.
Can CVE-2019-25411 lead to data breaches?
Yes, CVE-2019-25411 can lead to unauthorized script execution which may jeopardize the confidentiality and integrity of user data.