CVE-2019-25419

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed.
Configurations

Configuration 1 (hide)

cpe:2.3:a:comodo:dome_firewall:*:*:*:*:*:*:*:*

History

17 Jun 2026, 02:32

Type Values Removed Values Added
Summary
  • (es) Comodo Dome Cortafuegos 2.7.0 contiene una vulnerabilidad de cross-site scripting almacenado que permite a los atacantes inyectar scripts maliciosos al enviar entradas manipuladas al endpoint de programación. Los atacantes pueden enviar solicitudes POST con cargas útiles de JavaScript en el parámetro SCHNAME para ejecutar código arbitrario en los navegadores de los administradores cuando se accede a la página de programación.

20 Feb 2026, 17:17

Type Values Removed Values Added
CPE cpe:2.3:a:comodo:dome_firewall:*:*:*:*:*:*:*:*
First Time Comodo
Comodo dome Firewall
References () https://cdome.comodo.com/firewall/ - () https://cdome.comodo.com/firewall/ - Product
References () https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9278&af=9278 - () https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9278&af=9278 - Not Applicable
References () https://www.exploit-db.com/exploits/46408 - () https://www.exploit-db.com/exploits/46408 - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/comodo-dome-firewall-stored-cross-site-scripting-via-schedule - () https://www.vulncheck.com/advisories/comodo-dome-firewall-stored-cross-site-scripting-via-schedule - Third Party Advisory

19 Feb 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 13:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25419

Mitre link : CVE-2019-25419

CVE.ORG link : CVE-2019-25419


JSON object : View

Products Affected

comodo

  • dome_firewall
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')