Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 02 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comodo comodo Dome Firewall
|
|
| CPEs | cpe:2.3:a:comodo:comodo_dome_firewall:2.7.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Comodo comodo Dome Firewall
|
Fri, 20 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Comodo
Comodo dome Firewall |
|
| CPEs | cpe:2.3:a:comodo:dome_firewall:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Comodo
Comodo dome Firewall |
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cdome
Cdome comodo Dome Firewall |
|
| Vendors & Products |
Cdome
Cdome comodo Dome Firewall |
Thu, 19 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input through admin management parameters. Attackers can inject script payloads in the admin_name, name, and surname parameters via POST requests to the /korugan/admins endpoint, which are stored and executed when administrators access the interface. | |
| Title | Comodo Dome Firewall 2.7.0 Stored Cross-Site Scripting via admins | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-02T21:05:20.186Z
Reserved: 2026-02-18T22:37:36.783Z
Link: CVE-2019-25404
Updated: 2026-02-19T16:39:00.602Z
Status : Analyzed
Published: 2026-02-19T13:16:13.160
Modified: 2026-02-20T17:20:23.390
Link: CVE-2019-25404
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:07:10Z