CVE-2021-36946

Description

Microsoft Dynamics Business Central Cross-site Scripting Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages7 packages

CVEListV5microsoft/dynamics_365_business_central_spring_2019_update14.0.0Application Build 14.27.47563, Platform Build 14.0
CVEListV5microsoft/microsoft_dynamics_365_business_central_2020_release_wave_2_-_update_17.917.0Application Build 17.9.28504, Platform Build 17.0.
CVEListV5microsoft/microsoft_dynamics_365_business_central_2020_release_wave_1_-_update_16.1516.0Application Build 16.15.28500, Platform Build 16.0
CVEListV5microsoft/microsoft_dynamics_nav_20171.030601

Patches

🔴Vulnerability Details

4
OSV
linux-azure vulnerabilities2022-10-03
OSV
linux, linux-aws, linux-aws-hwe, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, lnux-hwe, inux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2022-09-21
GHSA
GHSA-2fq7-f2fp-mgxx: Microsoft Dynamics Business Central Cross-site Scripting Vulnerability2022-05-24
CVEList
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability2021-08-12

📋Vendor Advisories

1
Microsoft
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability2021-08-10
CVE-2021-36946 (MEDIUM CVSS 5.4) | Microsoft Dynamics Business Central | cvebase.io