CVE-2019-25424: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via https_exceptions
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input to the EXCEPTIONSITELIST parameter. Attackers can craft POST requests to the httpsexceptions endpoint with script payloads to execute arbitrary JavaScript in users' browsers and steal session data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25424?
CVE-2019-25424 is classified as a medium severity reflected cross-site scripting vulnerability.
How do I fix CVE-2019-25424?
To fix CVE-2019-25424, ensure that all user input is properly sanitized and validated before being processed by the EXCEPTIONSITELIST parameter.
What software is affected by CVE-2019-25424?
CVE-2019-25424 affects Comodo Dome Firewall version 2.7.0.
What is the impact of CVE-2019-25424?
The impact of CVE-2019-25424 allows attackers to inject and execute malicious scripts in the context of the victim's browser.
Can CVE-2019-25424 be exploited remotely?
Yes, CVE-2019-25424 can be exploited remotely by sending crafted requests containing unsanitized input.