CVE-2019-25417: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via QoS Rules
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the protocol parameter. Attackers can send POST requests to the QoS rules management endpoint with JavaScript payloads in the protocol parameter to execute arbitrary code in administrator browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25417?
CVE-2019-25417 is classified as a high-severity reflected cross-site scripting vulnerability.
How do I fix CVE-2019-25417?
To fix CVE-2019-25417, ensure that you sanitize and validate user input for the protocol parameter in Comodo Dome Firewall.
Who is affected by CVE-2019-25417?
CVE-2019-25417 affects users of Comodo Dome Firewall version 2.7.0.
What are the potential impacts of CVE-2019-25417?
The potential impacts of CVE-2019-25417 include unauthorized script execution in a user's browser, leading to data theft or session hijacking.
What is the nature of the attack vector in CVE-2019-25417?
The attack vector for CVE-2019-25417 involves submitting crafted input via POST requests to exploit the reflected cross-site scripting flaw.