First published: Wed Apr 15 2020(Updated: )
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This CVE ID is unique from CVE-2020-1049.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 Server | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1050 has a medium severity rating due to its potential impact on users via cross site scripting.
To fix CVE-2020-1050, apply the latest security updates provided by Microsoft for Dynamics 365 Server version 9.0.
CVE-2020-1050 can enable attackers to execute malicious scripts in the context of unsuspecting users, potentially leading to data theft or unauthorized actions.
CVE-2020-1050 affects Microsoft Dynamics 365 Server version 9.0 when not properly secured against crafted web requests.
Currently, Microsoft recommends updating to the latest version as the most effective way to mitigate CVE-2020-1050.