Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Comodo Dome Firewall 2.7.0 Allows Malicious Script Injection

CVE-2019-25405
Summary

The Comodo Dome Firewall has a security flaw that lets attackers inject malicious code into administrators' browsers. This can happen when an attacker sends a special type of request to the firewall's license activation page. To stay safe, update to the latest version of the firewall.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
comodo dome_firewall 2.7.0 –
Original title
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the newLicense parameter. Attackers ...
Original description
Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the newLicense parameter. Attackers can send POST requests to the license activation endpoint with script payloads in the newLicense field to execute arbitrary JavaScript in administrators' browsers.
nvd CVSS3.1 5.4
nvd CVSS4.0 5.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026