CVE-2019-25428: Comodo Dome Firewall 2.7.0 Cross-Site Scripting via openvpn_users
Comodo Dome Firewall 2.7.0 contains multiple reflected cross-site scripting vulnerabilities in the openvpnusers endpoint that allow attackers to inject malicious scripts through POST parameters. Attackers can submit crafted POST requests with script payloads in the username, remotenets, explicitroutes, staticip, customdns, or customdomain parameters to execute arbitrary JavaScript in users' browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25428?
CVE-2019-25428 is considered a high severity vulnerability due to its potential to allow attackers to inject malicious scripts.
How do I fix CVE-2019-25428?
To fix CVE-2019-25428, ensure that you apply the latest security updates and patches provided by Comodo for the Dome Firewall software.
What are the consequences of exploiting CVE-2019-25428?
Exploiting CVE-2019-25428 can lead to unauthorized access, data theft, and execution of malicious scripts in the context of the affected users.
How can I mitigate the risks associated with CVE-2019-25428?
To mitigate the risks of CVE-2019-25428, implement input validation and sanitization methods for all user inputs in the application.
Which versions of Comodo Dome Firewall are affected by CVE-2019-25428?
Comodo Dome Firewall version 2.7.0 is affected by CVE-2019-25428, and users of this version should take action to secure their systems.