Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.1
Comodo Dome Firewall: Malicious Scripts Can Be Injected
CVE-2019-25412
Summary
Comodo Dome Firewall 2.7.0 has a security flaw that lets hackers insert malicious code into users' browsers by sending them a specially crafted request. This could allow hackers to take control of a user's browser and steal sensitive information. Update to the latest version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| comodo | dome_firewall | 2.7.0 | – |
Original title
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input through the NTP_SERVER_LIST para...
Original description
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting unsanitized input through the NTP_SERVER_LIST parameter. Attackers can send POST requests to the /korugan/time endpoint with script payloads in the NTP_SERVER_LIST parameter to execute arbitrary JavaScript in users' browsers.
nvd CVSS3.1
6.1
nvd CVSS4.0
5.1
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
- https://cdome.comodo.com/firewall/ Product
- https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9278&af=92... Not Applicable
- https://www.exploit-db.com/exploits/46408 Exploit Third Party Advisory
- https://www.vulncheck.com/advisories/comodo-dome-firewall-reflected-cross-site-s... Broken Link
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026