Comodo Dome Firewall 2.7.0 contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the policyfw endpoint. Attackers can submit POST requests with JavaScript payloads in the mac, target, and remark parameters to execute arbitrary code in administrator browsers or store persistent scripts in the application.
History

Thu, 19 Feb 2026 12:30:00 +0000

Type Values Removed Values Added
Description Comodo Dome Firewall 2.7.0 contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the policyfw endpoint. Attackers can submit POST requests with JavaScript payloads in the mac, target, and remark parameters to execute arbitrary code in administrator browsers or store persistent scripts in the application.
Title Comodo Dome Firewall 2.7.0 Cross-Site Scripting via policyfw
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-19T12:02:36.913Z

Reserved: 2026-02-18T22:39:55.518Z

Link: CVE-2019-25421

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-19T13:16:16.540

Modified: 2026-02-19T13:16:16.540

Link: CVE-2019-25421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.