### [CVE-2024-56341](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56341) ![](https://img.shields.io/static/v1?label=Product&message=Content%20Navigator&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=3.0.11%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=3.0.15%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=3.1.0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Improper%20Neutralization%20of%20Input%20During%20Web%20Page%20Generation%20(XSS%20or%20'Cross-site%20Scripting')&color=brightgreen) ### Description IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. ### POC #### Reference No PoCs from references. #### Github - https://github.com/Sharpe-nl/CVEs - https://github.com/sT0wn-nl/CVEs