CVE-2019-25405

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the newLicense parameter. Attackers can send POST requests to the license activation endpoint with script payloads in the newLicense field to execute arbitrary JavaScript in administrators' browsers.
Configurations

Configuration 1 (hide)

cpe:2.3:a:comodo:dome_firewall:2.7.0:*:*:*:*:*:*:*

History

20 Feb 2026, 17:20

Type Values Removed Values Added
First Time Comodo
Comodo dome Firewall
References () https://cdome.comodo.com/firewall/ - () https://cdome.comodo.com/firewall/ - Product
References () https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9278&af=9278 - () https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9278&af=9278 - Not Applicable
References () https://www.exploit-db.com/exploits/46408 - () https://www.exploit-db.com/exploits/46408 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/comodo-dome-firewall-stored-cross-site-scripting-via-licenseactivation - () https://www.vulncheck.com/advisories/comodo-dome-firewall-stored-cross-site-scripting-via-licenseactivation - Broken Link
CPE cpe:2.3:a:comodo:dome_firewall:2.7.0:*:*:*:*:*:*:*

19 Feb 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 13:16

Updated : 2026-02-20 17:20


NVD link : CVE-2019-25405

Mitre link : CVE-2019-25405

CVE.ORG link : CVE-2019-25405


JSON object : View

Products Affected

comodo

  • dome_firewall
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')