Microsoft Dynamics 365 (On-Premises) Cross-Site Scripting Vulnerability Allowing Spoofing

Vulnerability

A cross-site scripting vulnerability has been identified in Microsoft Dynamics 365 (on-premises) version 9.1. This issue arises from improper neutralization of input during web page generation, allowing an unauthorized attacker to perform spoofing over the network.

Impact

Exploitation of this vulnerability could lead to spoofing attacks, allowing an attacker to impersonate another user or entity.

Remediation

Users can apply the security update available through the Microsoft Update Catalog to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.