Unrestricted upload of file with dangerous type in LenovoEMC NAS Firmware - CVE-2018-9078
Published: September 30, 2018
LenovoEMC NAS Firmware
Detailed vulnerability description
The vulnerability allows a remote attacker to upload dangerous files.
The vulnerability exists due to the web interface allows uploading of SVG files. A remote authenticated attacker can upload a malicious SVG file, trick the victim into opening it in the browser and execute arbitrary JavaScript code in the context of vulnerable application.