CVE-2019-25430: Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via vpn_users
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted input to the username parameter. Attackers can send POST requests to the vpnusers endpoint with script payloads in the username field to execute arbitrary JavaScript in victim browsers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25430?
CVE-2019-25430 is classified as a high severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
How do I fix CVE-2019-25430?
To fix CVE-2019-25430, upgrade to a patched version of Comodo Dome Firewall that addresses this reflected cross-site scripting vulnerability.
What is the impact of CVE-2019-25430?
The impact of CVE-2019-25430 allows attackers to execute malicious scripts in the context of the user's browser, potentially leading to data theft and session hijacking.
Who is affected by CVE-2019-25430?
CVE-2019-25430 affects users of Comodo Dome Firewall version 2.7.0 and potentially earlier versions.
Is there a workaround for CVE-2019-25430?
There are no officially recommended workarounds for CVE-2019-25430; updating the software is the best course of action.