CVE-2026-1243
EUVD-2026-1811202.04.2026, 01:16
IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ibm | content_navigator | 3.0.15 ≤ 𝑥 ≤ 1.11.0 |
| ibm | content_navigator | 3.1.0 |
| ibm | content_navigator | 3.2.0 |
𝑥
= Vulnerable software versions