Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed. | |
| Title | Comodo Dome Firewall 2.7.0 Stored Cross-Site Scripting via schedule | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-19T18:43:30.833Z
Reserved: 2026-02-18T22:39:37.782Z
Link: CVE-2019-25419
No data.
Status : Undergoing Analysis
Published: 2026-02-19T13:16:16.143
Modified: 2026-02-19T15:52:39.260
Link: CVE-2019-25419
No data.
OpenCVE Enrichment
No data.