First published: Thu May 21 2020(Updated: )
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 | =8.2 | |
Microsoft Dynamics 365 | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1063 has a severity rating of 'Important'.
To resolve CVE-2020-1063, apply the latest security updates provided by Microsoft for Dynamics 365.
CVE-2020-1063 affects Microsoft Dynamics 365 versions 8.2 and 9.0.
CVE-2020-1063 is classified as a cross-site scripting vulnerability.
Exploitation of CVE-2020-1063 could allow an attacker to execute malicious scripts in the context of the user’s session.