← back
CVE-2019-25410

Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via policy_routing

CVSS 5.1 MEDIUMEPSS 0.3%CWE-79
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through the source and destination parameters. Attackers can submit POST requests to the policy routing endpoint with script payloads in these parameters to execute arbitrary JavaScript in users' browsers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →