CVE-2025-49745
published 2025-08-12CVE-2025-49745: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to…
PriorityP427medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.51%
40.1th percentile
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | >= 9.1 < 9.1.38.10 | 9.1.38.10 |
| microsoft | microsoft_dynamics_365_version_9.1 | >= 9.0 < 9.1.38.10 | 9.1.38.10 |
| msrc | microsoft_dynamics_365_version_9.1 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93q5-8wfm-rh63: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized at
ghsa_unreviewed·2025-08-12
CVE-2025-49745 [MEDIUM] CWE-79 GHSA-93q5-8wfm-rh63: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized at
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
Microsoft
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
vendor_msrc·2025-08-12·CVSS 5.4
CVE-2025-49745 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Description: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability?
An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability).
FAQ: According to the CVSS metric, user interaction is requir
No detection rules found.
No public exploits indexed.
2025-08-12
Published