PT-2018-18842 · Iomega+1 · Iomega+1
Published
2018-09-28
·
Updated
2018-11-16
·
CVE-2018-9081
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier
Description
The issue affects the Content Viewer application, where file names used for assets are vulnerable to self cross-site scripting (self-XSS). This allows adversaries to add files to shares with a cross-site scripting payload in the file name. When a user attempts to rename the file, the payload is triggered.
Recommendations
For versions 4.1.402.34662 and earlier, consider restricting access to the Content Viewer application until a fix is available. As a temporary workaround, avoid renaming files with suspicious names in the Content Viewer to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iomega
Lenovoemc Nas