First published: Wed Nov 14 2018(Updated: )
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8607, CVE-2018-8608.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 | >=8.0<8.2.3.0003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8606 is classified as a moderate severity cross site scripting vulnerability.
To fix CVE-2018-8606, ensure that you update Microsoft Dynamics 365 (on-premises) to a version that properly sanitizes input.
CVE-2018-8606 affects Microsoft Dynamics 365 (on-premises) version 8.0 to 8.2.3.0003.
CVE-2018-8606 is a cross site scripting (XSS) vulnerability that allows execution of malicious scripts.
You should monitor for any unusual web activity and ensure proper input validation in your instance of Dynamics 365.