CVE-2019-25420

MEDIUM

Comodo Dome Firewall 2.7.0 - XSS

Title source: llm

Description

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the snat endpoint. Attackers can send POST requests with JavaScript payloads in the port or snat_to_ip parameters to execute arbitrary scripts in users' browsers.

Exploits (1)

exploitdb WORKING POC
by Ozer Goker · textwebappsmultiple
https://www.exploit-db.com/exploits/46408

Scores

CVSS v3 6.1
EPSS 0.0004
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (1)

comodo/dome_firewall < 2.7.0

Timeline

Published Feb 19, 2026
Tracked Since Feb 19, 2026