VYPR
Unrated severityNVD Advisory· Published Feb 19, 2026· Updated Mar 2, 2026

Comodo Dome Firewall 2.7.0 Stored Cross-Site Scripting via schedule

CVE-2019-25419

Description

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in administrators' browsers when the schedule page is accessed.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.