Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.
Published: 2018-09-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-20681 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.
History

No history.

Subscriptions

Lenovo Ez Media \& Backup Center Ez Media \& Backup Center Firmware Ix2 Ix2 Firmware Ix4-300d Ix4-300d Firmware Px12-400r Px12-400r Firmware Px12-450r Px12-450r Firmware Px2-300d Px2-300d Firmware Px4-300d Px4-300d Firmware Px4-300r Px4-300r Firmware Px4-400d Px4-400d Firmware Px4-400r Px4-400r Firmware Px6-300d Px6-300d Firmware Storcenter Ix2 Storcenter Ix2-dl Storcenter Ix2-dl Firmware Storcenter Ix2 Firmware Storcenter Ix4-300d Storcenter Ix4-300d Firmware Storcenter Px12-400r Storcenter Px12-400r Firmware Storcenter Px12-450r Storcenter Px12-450r Firmware Storcenter Px2-300d Storcenter Px2-300d Firmware Storcenter Px4-300d Storcenter Px4-300d Firmware Storcenter Px4-300r Storcenter Px4-300r Firmware Storcenter Px6-300d Storcenter Px6-300d Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-05T07:17:50.689Z

Reserved: 2018-03-27T00:00:00.000Z

Link: CVE-2018-9078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-28T20:29:01.097

Modified: 2024-11-21T04:14:55.757

Link: CVE-2018-9078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses