cbcvebase.
CVE-2025-49745
published 2025-08-12

CVE-2025-49745: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to…

PriorityP427medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.51%
40.1th percentile
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftdynamics_365>= 9.1 < 9.1.38.109.1.38.10
microsoftmicrosoft_dynamics_365_version_9.1>= 9.0 < 9.1.38.109.1.38.10
msrcmicrosoft_dynamics_365_version_9.1

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.