Cross-site Scripting Vulnerability Impacts Dynamics 365 (on-premises)
CVE-2024-38211
8.2HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2024-38211?
A cross-site scripting vulnerability in Microsoft Dynamics 365 (on-premises) enables an attacker to inject arbitrary web script or HTML into a user's browser session. This could lead to unauthorized actions or exposure of sensitive information, as affected users may be tricked into executing scripts that compromise their security. It is crucial for organizations using Microsoft Dynamics 365 on-premises to apply necessary patches and updates to mitigate potential exploitation of this vulnerability.
Affected Version(s)
Microsoft Dynamics 365 (on-premises) version 9.1 Unknown 9.0 < 1.31