First published: Wed Nov 14 2018(Updated: )
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8606, CVE-2018-8607, CVE-2018-8608.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 | >=8.0<8.2.3.0003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8605 has a severity rating of medium, indicating a moderate impact on affected systems.
To fix CVE-2018-8605, update Microsoft Dynamics 365 (on-premises) version 8 to a secure version above 8.2.3.0003.
The potential impacts of CVE-2018-8605 include exploitation through cross-site scripting, which may lead to data theft or session hijacking.
CVE-2018-8605 affects Microsoft Dynamics 365 (on-premises) version 8 prior to version 8.2.3.0004.
To determine if CVE-2018-8605 has been exploited, review access logs for unusual or unauthorized web requests targeting your Dynamics 365 server.