CVE-2019-25419

HIGH

Comodo Dome Firewall 2.7.0 - Stored XSS

Title source: llm
STIX 2.1

Description

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed.

Exploits (1)

exploitdb WORKING POC
by Ozer Goker · textwebappsmultiple
https://www.exploit-db.com/exploits/46408

References (4)

Core 4

Scores

CVSS v3 7.2
EPSS 0.0002
EPSS Percentile 5.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
comodo/dome_firewall < 2.7.0
Published Feb 19, 2026
Tracked Since Feb 19, 2026