Microsoft Dynamics 365 Field Service Cross-Site Scripting Vulnerability Allowing Spoofing

Vulnerability

A cross-site scripting vulnerability has been identified in Microsoft Dynamics 365 Field Service (online). This issue arises from improper input neutralization during web page generation, allowing an authorized attacker to perform spoofing over the network. The vulnerability affects several different versions and ranges of the application.

Impact

Exploitation of this vulnerability could lead to spoofing, with malicious scripts executing in the context of the victim's browser.

Remediation

Customers using Dynamics 365 Field Service (online) should visit the Power Platform admin center to apply the necessary updates. More information on updating the Field Service app can be found in the release notes.

Added: Nov 11, 2025, 6:54 PM
Updated: Nov 11, 2025, 6:54 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.9
exploitability
3.0
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.