Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.
Published: 2018-09-28
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-20684 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.
History

No history.

Subscriptions

Lenovo Ez Media \& Backup Center Ez Media \& Backup Center Firmware Ix2 Ix2 Firmware Ix4-300d Ix4-300d Firmware Px12-400r Px12-400r Firmware Px12-450r Px12-450r Firmware Px2-300d Px2-300d Firmware Px4-300d Px4-300d Firmware Px4-300r Px4-300r Firmware Px4-400d Px4-400d Firmware Px4-400r Px4-400r Firmware Px6-300d Px6-300d Firmware Storcenter Ix2 Storcenter Ix2-dl Storcenter Ix2-dl Firmware Storcenter Ix2 Firmware Storcenter Ix4-300d Storcenter Ix4-300d Firmware Storcenter Px12-400r Storcenter Px12-400r Firmware Storcenter Px12-450r Storcenter Px12-450r Firmware Storcenter Px2-300d Storcenter Px2-300d Firmware Storcenter Px4-300d Storcenter Px4-300d Firmware Storcenter Px4-300r Storcenter Px4-300r Firmware Storcenter Px6-300d Storcenter Px6-300d Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-05T07:17:50.658Z

Reserved: 2018-03-27T00:00:00.000Z

Link: CVE-2018-9081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-28T20:29:01.423

Modified: 2024-11-21T04:14:56.240

Link: CVE-2018-9081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses