CVE-2019-25422: Comodo Dome Firewall 2.7.0 Cross-Site Scripting via vpnfw
Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the vpnfw endpoint. Attackers can submit POST requests with script payloads in the target parameter for reflected XSS or the remark parameter for stored XSS to execute arbitrary JavaScript in administrator browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25422?
CVE-2019-25422 has a medium severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2019-25422?
You can mitigate CVE-2019-25422 by ensuring that the Comodo Dome Firewall is updated to the latest version that addresses this vulnerability.
What types of attacks can CVE-2019-25422 facilitate?
CVE-2019-25422 can facilitate cross-site scripting attacks that allow attackers to inject malicious scripts.
Who is affected by CVE-2019-25422?
CVE-2019-25422 affects users of Comodo Dome Firewall version 2.7.0.
How does CVE-2019-25422 exploit Cross-Site Scripting?
CVE-2019-25422 exploits Cross-Site Scripting by allowing attackers to submit POST requests with script payloads through the vpnfw endpoint.