Msrc Microsoft Dynamics 365 Version 9.1 vulnerabilities
45 known vulnerabilities affecting msrc/microsoft_dynamics_365_version_9.1.
Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH22MEDIUM23
Vulnerabilities
Page 1 of 3
CVE-2025-62206MEDIUMCVSS 6.52025-11-11
CVE-2025-62206 [MEDIUM] CWE-200 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker
msrc
CVE-2025-53728MEDIUMCVSS 6.52025-08-12
CVE-2025-53728 [MEDIUM] CWE-200 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would hav
msrc
CVE-2025-49745MEDIUMCVSS 5.42025-08-12
CVE-2025-49745 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Description: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confiden
msrc
CVE-2024-43476HIGHCVSS 7.62024-09-10
CVE-2024-43476 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to navigate to a page with malicious content to be compromised by the attacker.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of i
msrc
CVE-2024-38211HIGHCVSS 8.22024-08-13
CVE-2024-38211 [HIGH] CWE-601 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: According to the CVSS metric, a suc
msrc
CVE-2024-30061HIGHCVSS 7.32024-07-09
CVE-2024-30061 [HIGH] CWE-285 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is low (PR:L). What does that mean for this vulnerability?
An authorized attacker must be on the network to monitor domain network traffic (PR:L) while monitoring for user (UI:R) generated network traffic, or alternatively tha
msrc
CVE-2024-35263MEDIUMCVSS 5.72024-06-11
CVE-2024-35263 [MEDIUM] CWE-200 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: What type of information could be disclosed by this vulnerability?
This vulnerabil
msrc
CVE-2024-21419HIGHCVSS 7.62024-03-12
CVE-2024-21419 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authorized attacker with read/write privileges must send a victim a malicious email, or share the link to a malicious email, and convince them to open it.
FAQ: Accordin
msrc
CVE-2024-21389HIGHCVSS 7.62024-02-13
CVE-2024-21389 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean f
msrc
CVE-2024-21328HIGHCVSS 7.62024-02-13
CVE-2024-21328 [HIGH] CWE-79 Dynamics 365 Sales Spoofing Vulnerability
Dynamics 365 Sales Spoofing Vulnerability
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
The vulnerability is in the web server, but the malicious scripts execute in the victim’s browser on their machine.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authentica
msrc
CVE-2024-21394HIGHCVSS 7.62024-02-13
CVE-2024-21394 [HIGH] CWE-79 Dynamics 365 Field Service Spoofing Vulnerability
Dynamics 365 Field Service Spoofing Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that
msrc
CVE-2024-21395HIGHCVSS 8.22024-02-13
CVE-2024-21395 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity
msrc
CVE-2024-21393HIGHCVSS 7.62024-02-13
CVE-2024-21393 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
The vulnerability is in the web server, but the malicious scripts execute in the victim’s browser on their machine.
FAQ: According to the CVSS metric, successful exploitation of this v
msrc
CVE-2024-21396HIGHCVSS 7.62024-02-13
CVE-2024-21396 [HIGH] CWE-79 Dynamics 365 Sales Spoofing Vulnerability
Dynamics 365 Sales Spoofing Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What
msrc
CVE-2023-36020HIGHCVSS 7.62023-12-12
CVE-2023-36020 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: According to the CVSS metric, privil
msrc
CVE-2023-36410HIGHCVSS 7.62023-11-14
CVE-2023-36410 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity
msrc
CVE-2023-36031HIGHCVSS 7.62023-11-14
CVE-2023-36031 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.
FAQ: According to the CVSS metric, user i
msrc
CVE-2023-36030MEDIUMCVSS 6.12023-11-14
CVE-2023-36030 [MEDIUM] CWE-79 Microsoft Dynamics 365 Sales Spoofing Vulnerability
Microsoft Dynamics 365 Sales Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would need to click on a specially crafted URL that could present a popup box requesting additional user input.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this
msrc
CVE-2023-36016MEDIUMCVSS 6.22023-11-14
CVE-2023-36016 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean
msrc
CVE-2023-36433MEDIUMCVSS 6.52023-10-10
CVE-2023-36433 [MEDIUM] CWE-643 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: What type of information could be disclosed by this vulnerability?
The type of inf
msrc
1 / 3Next →