Comodo Dome Firewall 2.7.0 contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the policyfw endpoint. Attackers can submit POST requests with JavaScript payloads in the mac, target, and remark parameters to execute arbitrary code in administrator browsers or store persistent scripts in the application.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Comodo Dome Firewall 2.7.0 contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the policyfw endpoint. Attackers can submit POST requests with JavaScript payloads in the mac, target, and remark parameters to execute arbitrary code in administrator browsers or store persistent scripts in the application. | |
| Title | Comodo Dome Firewall 2.7.0 Cross-Site Scripting via policyfw | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-19T16:29:36.836Z
Reserved: 2026-02-18T22:39:55.518Z
Link: CVE-2019-25421
Updated: 2026-02-19T16:29:29.678Z
Status : Undergoing Analysis
Published: 2026-02-19T13:16:16.540
Modified: 2026-02-19T15:52:39.260
Link: CVE-2019-25421
No data.
OpenCVE Enrichment
No data.