CVE-2019-25425

MEDIUM

Comodo Dome Firewall 2.7.0 - XSS

Title source: llm
STIX 2.1

Description

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the VIRUS_ADMIN parameter. Attackers can send POST requests to the smtpconfig endpoint with script payloads to execute arbitrary JavaScript in the context of an administrator's browser session.

Exploits (1)

exploitdb WORKING POC
by Ozer Goker · textwebappsmultiple
https://www.exploit-db.com/exploits/46408

Scores

CVSS v3 6.1
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
comodo/dome_firewall < 2.7.0
Published Feb 19, 2026
Tracked Since Feb 19, 2026