First published: Wed Nov 14 2018(Updated: )
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8606, CVE-2018-8608.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 | >=8.0<8.2.3.0003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8607 is rated as a critical security vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2018-8607, update Microsoft Dynamics 365 (on-premises) to the latest patched version as recommended by Microsoft.
CVE-2018-8607 affects Microsoft Dynamics 365 (on-premises) version 8, specifically versions between 8.0 and 8.2.3.0003.
Exploitation of CVE-2018-8607 can allow attackers to execute arbitrary scripts in the context of a user's session in Dynamics 365.
Currently, there are no official workarounds for CVE-2018-8607, so upgrading to a secure version is essential.