CVE-2019-25419: Comodo Dome Firewall 2.7.0 Stored Cross-Site Scripting via schedule
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25419?
The severity of CVE-2019-25419 is classified as high due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2019-25419?
To fix CVE-2019-25419, update Comodo Dome Firewall to the latest version provided by the vendor.
What type of vulnerability is CVE-2019-25419?
CVE-2019-25419 is a stored cross-site scripting (XSS) vulnerability.
What impact does CVE-2019-25419 have on users?
CVE-2019-25419 can allow attackers to execute malicious scripts in the context of an authenticated user's session.
Who is affected by CVE-2019-25419?
CVE-2019-25419 affects users of Comodo Dome Firewall version 2.7.0.