CVE-2019-25418: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via fwgroups
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the FWADDRESSES parameter. Attackers can send POST requests to the /korugan/fwgroups endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25418?
CVE-2019-25418 is a high-severity reflected cross-site scripting vulnerability.
How do I fix CVE-2019-25418?
To fix CVE-2019-25418, ensure that input validation and output encoding are implemented on the FWADDRESSES parameter.
What are the potential impacts of CVE-2019-25418?
The potential impacts of CVE-2019-25418 include the execution of arbitrary JavaScript in the context of the victim's browser.
Which software versions are affected by CVE-2019-25418?
CVE-2019-25418 specifically affects Comodo Dome Firewall version 2.7.0.
Is it possible to exploit CVE-2019-25418 remotely?
Yes, CVE-2019-25418 can be exploited remotely by sending crafted POST requests.