CVE-2019-25404
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input through admin management parameters. Attackers can inject script payloads in the admin_name, name, and surname parameters via POST requests to the /korugan/admins endpoint, which are stored and executed when administrators access the interface.
Vendor
Product
CWE
Yayın Tarihi
2026-02-19 13:16:13
Güncelleme
2026-02-20 17:20:23
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-