CVE-2019-25427: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via antispyware
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the antispyware endpoint. Attackers can send POST requests with JavaScript payloads in the DNSMASQWHITELIST or DNSMASQBLACKLIST parameters to execute arbitrary code in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25427?
CVE-2019-25427 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2019-25427?
To fix CVE-2019-25427, ensure that you apply the latest patches from Comodo for the Dome Firewall.
What types of attacks can CVE-2019-25427 enable?
CVE-2019-25427 can enable attackers to perform reflected cross-site scripting attacks, potentially compromising user data.
Which versions of Comodo Dome Firewall are affected by CVE-2019-25427?
CVE-2019-25427 affects Comodo Dome Firewall version 2.7.0.
Is CVE-2019-25427 exploitable remotely?
Yes, CVE-2019-25427 is exploitable remotely because it allows attackers to send crafted requests to the antispyware endpoint.