CVE-2019-25413: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via ID Parameter
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the /manage/ips/rules/ endpoint with script payloads in the ID parameter to execute arbitrary JavaScript in victim browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25413?
CVE-2019-25413 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2019-25413?
To fix CVE-2019-25413, ensure that you are using a patched version of Comodo Dome Firewall that addresses this vulnerability.
What type of attack is possible with CVE-2019-25413?
CVE-2019-25413 allows attackers to perform reflected cross-site scripting attacks by injecting malicious scripts through the ID parameter.
Who is affected by CVE-2019-25413?
CVE-2019-25413 affects users of Comodo Dome Firewall version 2.7.0.
Can CVE-2019-25413 be exploited remotely?
Yes, CVE-2019-25413 can be exploited remotely by unauthenticated attackers.