Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-38164
7.6HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 12 September 2023
What is CVE-2023-38164?
This vulnerability allows an attacker to inject malicious scripts into web pages displayed to users of Microsoft Dynamics 365 (on-premises). An attacker exploiting this vulnerability can execute unauthorized actions on behalf of a user, potentially exposing sensitive user data or facilitating phishing attacks. It's critical for organizations using Dynamics 365 (on-premises) to apply the latest security updates and best practices to mitigate these risks.
Affected Version(s)
Microsoft Dynamics 365 (on-premises) version 9.0 Unknown 9.0.0 < 9.0.49.04
Microsoft Dynamics 365 (on-premises) version 9.1 Unknown 9.0 < 9.1.21.05