Microsoft Dynamics 365 Field Service
cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:*:*:*, +1 more
A cross-site scripting vulnerability has been identified in Microsoft Dynamics 365 Field Service (online). This issue arises from improper input neutralization during web page generation, allowing an authorized attacker to perform spoofing over the network. The vulnerability affects several different versions and ranges of the application.
Exploitation of this vulnerability could lead to spoofing, with malicious scripts executing in the context of the victim's browser.
Customers using Dynamics 365 Field Service (online) should visit the Power Platform admin center to apply the necessary updates. More information on updating the Field Service app can be found in the release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.