Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

Comodo Dome Firewall: Malicious Scripts Can Be Injected

CVE-2019-25412
Summary

Comodo Dome Firewall 2.7.0 has a security flaw that lets hackers insert malicious code into users' browsers by sending them a specially crafted request. This could allow hackers to take control of a user's browser and steal sensitive information. Update to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
comodo dome_firewall 2.7.0 –
Original title
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input through the NTP_SERVER_LIST para...
Original description
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input through the NTP_SERVER_LIST parameter. Attackers can send POST requests to the /korugan/time endpoint with script payloads in the NTP_SERVER_LIST parameter to execute arbitrary JavaScript in users' browsers.
nvd CVSS3.1 6.1
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026