CVE-2023-36016Cross-site Scripting in Microsoft Dynamics 365 Version 9.0

Severity
3.4LOWNVD
CNA6.2
EPSS
0.2%
top 63.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateJul 30

Description

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:NExploitability: 1.7 | Impact: 1.4

Affected Packages3 packages

NVDmicrosoft/dynamics_3659.09.0.51.06+1
CVEListV5microsoft/microsoft_dynamics_365_version_9.09.0.09.0.51.06

Patches

🔴Vulnerability Details

3
OSV
linux-aws-5.15, linux-ibm, linux-ibm-5.15, linux-raspi vulnerabilities2024-07-30
CVEList
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability2023-11-14
GHSA
GHSA-38fm-2h4v-3qf4: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability2023-11-14

📋Vendor Advisories

1
Microsoft
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability2023-11-14
CVE-2023-36016 — Cross-site Scripting in Microsoft | cvebase