First published: Wed Nov 14 2018(Updated: )
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This CVE ID is unique from CVE-2018-8605, CVE-2018-8606, CVE-2018-8607.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 (on-premises) | >=8.0<8.2.3.0003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8608 has a medium severity rating due to its potential for enabling cross-site scripting attacks.
CVE-2018-8608 affects Microsoft Dynamics 365 (on-premises) version 8 up to version 8.2.3.0003.
To fix CVE-2018-8608, ensure your Microsoft Dynamics 365 (on-premises) version is updated to the latest patch provided by Microsoft.
CVE-2018-8608 allows attackers to perform cross-site scripting (XSS) attacks by sending specially crafted web requests.
Users of Microsoft Dynamics 365 should apply the necessary updates to mitigate the risks posed by CVE-2018-8608.