CVE-2018-9081 Details
Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24224 | CVE | Vendor Advisory |
| https://support.lenovo.com/us/en/solutions/LEN-24224 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lenovo storcenter px12-450r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px12-450r | All versions |
CPE
Remediation
| |
| lenovo storcenter px12-400r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px12-400r | All versions |
CPE
Remediation
| |
| lenovo storcenter px4-300r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px4-300r | All versions |
CPE
Remediation
| |
| lenovo storcenter px6-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px6-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter px4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px4-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter px2-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px2-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter ix4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter ix4-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter ix2 firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter ix2 | All versions |
CPE
Remediation
| |
| lenovo storcenter ix2-dl firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter ix2-dl | All versions |
CPE
Remediation
| |
| lenovo ez media & backup center firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo ez media & backup center | All versions |
CPE
Remediation
| |
| lenovo px12-450r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px12-450r | All versions |
CPE
Remediation
| |
| lenovo px12-400r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px12-400r | All versions |
CPE
Remediation
| |
| lenovo px4-400r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-400r | All versions |
CPE
Remediation
| |
| lenovo px4-300r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-300r | All versions |
CPE
Remediation
| |
| lenovo px6-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px6-300d | All versions |
CPE
Remediation
| |
| lenovo px4-400d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-400d | All versions |
CPE
Remediation
| |
| lenovo px4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-300d | All versions |
CPE
Remediation
| |
| lenovo px2-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px2-300d | All versions |
CPE
Remediation
| |
| lenovo ix4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo ix4-300d | All versions |
CPE
Remediation
| |
| lenovo ix2 firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo ix2 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 16, 2018 | Initial Analysis | [email protected] |