Msrc Microsoft Dynamics 365 Version 9.1 vulnerabilities
45 known vulnerabilities affecting msrc/microsoft_dynamics_365_version_9.1.
Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH22MEDIUM23
Vulnerabilities
Page 2 of 3
CVE-2023-36429MEDIUMCVSS 6.52023-10-10
CVE-2023-36429 [MEDIUM] CWE-643 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: What type of information could be disclosed by this vulnerability?
The type of inf
msrc
CVE-2023-36416MEDIUMCVSS 6.12023-10-10
CVE-2023-36416 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability?
Limited information from the victim's browser associated with the vulnerable URL can be sent to the attacker by the malicious code.
FAQ: According t
msrc
CVE-2023-36886HIGHCVSS 7.62023-09-12
CVE-2023-36886 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity
msrc
CVE-2023-38164HIGHCVSS 7.62023-09-12
CVE-2023-38164 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would
msrc
CVE-2023-33171HIGHCVSS 8.22023-07-11
CVE-2023-33171 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean f
msrc
CVE-2023-35335HIGHCVSS 8.22023-07-11
CVE-2023-35335 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability?
There could be a loss of confidentiality if an unaware user clicked on a popup therefore creating an opportunity for an attacker to retrieve cookies o
msrc
CVE-2023-28309HIGHCVSS 7.62023-04-11
CVE-2023-28309 [HIGH] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would need to click on a specially crafted URL that could present a popup box requesting additional user input.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope chang
msrc
CVE-2023-28314MEDIUMCVSS 6.12023-04-11
CVE-2023-28314 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability?
Information in the victim's browser associated with the vulnerable URL can be read by the malicious JavaScript code and sent to the attacker.
FAQ: A
msrc
CVE-2023-24919MEDIUMCVSS 5.42023-03-14
CVE-2023-24919 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would need to click on a specially crafted URL that could present a popup box requesting additional user input.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope cha
msrc
CVE-2023-24922MEDIUMCVSS 6.52023-03-14
CVE-2023-24922 [MEDIUM] CWE-643 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
This vulnerability causes a verbose error message that could provide attacker with enough information to construct a malicious payload.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerabili
msrc
CVE-2023-24891MEDIUMCVSS 5.42023-03-14
CVE-2023-24891 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L)? What does that mean for this vulnerability?
Information in the victim's browser associated with the vulnerable URL can be read by the malicious JavaScript code and sent to the attacker.
FAQ: A
msrc
CVE-2023-24920MEDIUMCVSS 5.42023-03-14
CVE-2023-24920 [MEDIUM] CWE-352 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
A user could be tricked into entering credentials or responding to a pop up after opening a specially crafted file or clicking on a link, typically by way of an enticement in an emai
msrc
CVE-2023-24921MEDIUMCVSS 5.42023-03-14
CVE-2023-24921 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction wou
msrc
CVE-2023-24879MEDIUMCVSS 5.42023-03-14
CVE-2023-24879 [MEDIUM] Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the
msrc
CVE-2023-21573MEDIUMCVSS 5.42023-02-14
CVE-2023-21573 [MEDIUM] Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would need to click on a specially crafted URL that could present a popup box requesting additional user input.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:
msrc
CVE-2023-21571MEDIUMCVSS 5.42023-02-14
CVE-2023-21571 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would need to click on a specially crafted URL that could present a popup box requesting additional user input.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that m
msrc
CVE-2023-21570MEDIUMCVSS 5.42023-02-14
CVE-2023-21570 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
An
msrc
CVE-2023-21572MEDIUMCVSS 6.52023-02-14
CVE-2023-21572 [MEDIUM] Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would need to click on a specially crafted URL that could present a popup box requesting additional user input.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for
msrc
CVE-2023-21807MEDIUMCVSS 6.52023-02-14
CVE-2023-21807 [MEDIUM] CWE-79 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS metric, user interaction is
msrc
CVE-2022-23259HIGHCVSS 8.82022-04-12
CVE-2022-23259 [HIGH] Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.
Microsoft Dynamics: Microsoft Dynamics
Microsoft: Microsof
msrc