CVE-2019-25412: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via NTP_SERVER_LIST
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input through the NTPSERVERLIST parameter. Attackers can send POST requests to the /korugan/time endpoint with script payloads in the NTPSERVERLIST parameter to execute arbitrary JavaScript in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25412?
CVE-2019-25412 is classified as a reflected cross-site scripting vulnerability that can lead to significant security risks.
How do I fix CVE-2019-25412?
To remediate CVE-2019-25412, ensure that input parameters like NTP_SERVER_LIST are properly sanitized to prevent script injection.
What type of vulnerability is CVE-2019-25412?
CVE-2019-25412 is a reflected cross-site scripting vulnerability that affects Comodo Dome Firewall.
Which software versions are affected by CVE-2019-25412?
CVE-2019-25412 specifically affects Comodo Dome Firewall version 2.7.0.
What can attackers do with CVE-2019-25412?
Attackers exploiting CVE-2019-25412 can inject malicious scripts that may hijack user sessions or redirect users to malicious sites.