cbcvebase.

Msrc Microsoft Dynamics 365 Version 9.0 vulnerabilities

52 known vulnerabilities affecting msrc/microsoft_dynamics_365_version_9.0.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH18MEDIUM34

Vulnerabilities

Page 1 of 3
CVE-2023-36020HIGHCVSS 7.62023-12-12
CVE-2023-36020 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site. FAQ: According to the CVSS metric, privil
msrc
CVE-2023-36030MEDIUMCVSS 6.12023-11-14
CVE-2023-36030 [MEDIUM] CWE-79 Microsoft Dynamics 365 Sales Spoofing Vulnerability Microsoft Dynamics 365 Sales Spoofing Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would need to click on a specially crafted URL that could present a popup box requesting additional user input. FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this
msrc
CVE-2023-36016MEDIUMCVSS 6.22023-11-14
CVE-2023-36016 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker. FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean
msrc
CVE-2023-36433MEDIUMCVSS 6.52023-10-10
CVE-2023-36433 [MEDIUM] CWE-643 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges. FAQ: What type of information could be disclosed by this vulnerability? The type of inf
msrc
CVE-2023-36429MEDIUMCVSS 6.52023-10-10
CVE-2023-36429 [MEDIUM] CWE-643 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges. FAQ: What type of information could be disclosed by this vulnerability? The type of inf
msrc
CVE-2023-36416MEDIUMCVSS 6.12023-10-10
CVE-2023-36416 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability? Limited information from the victim's browser associated with the vulnerable URL can be sent to the attacker by the malicious code. FAQ: According t
msrc
CVE-2023-36886HIGHCVSS 7.62023-09-12
CVE-2023-36886 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker. FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity
msrc
CVE-2023-38164HIGHCVSS 7.62023-09-12
CVE-2023-38164 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would
msrc
CVE-2023-35389MEDIUMCVSS 6.52023-08-08
CVE-2023-35389 [MEDIUM] CWE-611 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? A user could be tricked into entering credentials or responding to a pop up after opening a specially crafted file or clicking on a link, typically by way of an enticement in an email
msrc
CVE-2023-33171HIGHCVSS 8.22023-07-11
CVE-2023-33171 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker. FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean f
msrc
CVE-2023-35335HIGHCVSS 8.22023-07-11
CVE-2023-35335 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability? There could be a loss of confidentiality if an unaware user clicked on a popup therefore creating an opportunity for an attacker to retrieve cookies o
msrc
CVE-2023-28309HIGHCVSS 7.62023-04-11
CVE-2023-28309 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would need to click on a specially crafted URL that could present a popup box requesting additional user input. FAQ: According to the CVSS metric, a successful exploitation could lead to a scope chang
msrc
CVE-2023-28314MEDIUMCVSS 6.12023-04-11
CVE-2023-28314 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability? Information in the victim's browser associated with the vulnerable URL can be read by the malicious JavaScript code and sent to the attacker. FAQ: A
msrc
CVE-2023-24919MEDIUMCVSS 5.42023-03-14
CVE-2023-24919 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would need to click on a specially crafted URL that could present a popup box requesting additional user input. FAQ: According to the CVSS metric, a successful exploitation could lead to a scope cha
msrc
CVE-2023-24922MEDIUMCVSS 6.52023-03-14
CVE-2023-24922 [MEDIUM] CWE-643 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? This vulnerability causes a verbose error message that could provide attacker with enough information to construct a malicious payload. FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerabili
msrc
CVE-2023-24891MEDIUMCVSS 5.42023-03-14
CVE-2023-24891 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability? Information in the victim's browser associated with the vulnerable URL can be read by the malicious JavaScript code and sent to the attacker. FAQ: A
msrc
CVE-2023-24920MEDIUMCVSS 5.42023-03-14
CVE-2023-24920 [MEDIUM] CWE-352 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? A user could be tricked into entering credentials or responding to a pop up after opening a specially crafted file or clicking on a link, typically by way of an enticement in an emai
msrc
CVE-2023-24921MEDIUMCVSS 5.42023-03-14
CVE-2023-24921 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction wou
msrc
CVE-2023-24879MEDIUMCVSS 5.42023-03-14
CVE-2023-24879 [MEDIUM] Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges. FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the
msrc
CVE-2023-21573MEDIUMCVSS 5.42023-02-14
CVE-2023-21573 [MEDIUM] Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would need to click on a specially crafted URL that could present a popup box requesting additional user input. FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:
msrc