CVE-2019-25425: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via smtpconfig
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the VIRUSADMIN parameter. Attackers can send POST requests to the smtpconfig endpoint with script payloads to execute arbitrary JavaScript in the context of an administrator's browser session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25425?
CVE-2019-25425 is classified as a moderate severity vulnerability due to its potential to enable reflected cross-site scripting attacks.
How do I fix CVE-2019-25425?
To fix CVE-2019-25425, ensure that the Comodo Dome Firewall is updated to the latest version that addresses this vulnerability.
What type of attacks can CVE-2019-25425 facilitate?
CVE-2019-25425 can facilitate reflected cross-site scripting attacks, allowing attackers to execute malicious scripts in the context of a victim's browser.
Who is affected by CVE-2019-25425?
CVE-2019-25425 affects users of Comodo Dome Firewall version 2.7.0.
What does CVE-2019-25425 exploit?
CVE-2019-25425 exploits the VIRUS_ADMIN parameter in Comodo Dome Firewall to inject malicious scripts.