CVE-2019-25414: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via ID Parameter Appid
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the ID parameter. Attackers can craft requests to the /manage/ips/appid/ endpoint with script payloads in the ID parameter to execute arbitrary JavaScript in victim browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25414?
The severity of CVE-2019-25414 is considered medium due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2019-25414?
To fix CVE-2019-25414, update to the latest version of Comodo Dome Firewall or implement input validation on the ID parameter.
Who is affected by CVE-2019-25414?
CVE-2019-25414 affects users of Comodo Dome Firewall version 2.7.0.
What type of vulnerability is CVE-2019-25414?
CVE-2019-25414 is a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2019-25414 be exploited remotely?
Yes, CVE-2019-25414 can be exploited remotely by unauthenticated attackers using crafted input.