CVE-2019-25420: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via snat
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the snat endpoint. Attackers can send POST requests with JavaScript payloads in the port or snattoip parameters to execute arbitrary scripts in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25420?
CVE-2019-25420 has been classified as a medium severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2019-25420?
To fix CVE-2019-25420, ensure to update Comodo Dome Firewall to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2019-25420?
CVE-2019-25420 is a reflected cross-site scripting vulnerability that allows for the injection of malicious scripts.
Who is affected by CVE-2019-25420?
CVE-2019-25420 affects users of Comodo Dome Firewall version 2.7.0.
What can attackers do with CVE-2019-25420?
Attackers can exploit CVE-2019-25420 to execute arbitrary JavaScript in the context of the user's session by crafting malicious input to the snat endpoint.