First published: Thu Feb 25 2021(Updated: )
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 Business Central | =2019-release_wave_2 | |
Microsoft Dynamics 365 Business Central | =2020-release_wave_1 | |
Microsoft Dynamics 365 Business Central | =2020-release_wave_2 | |
Microsoft Dynamics NAV 2018 | =2015 | |
Microsoft Dynamics NAV 2018 | =2016 | |
Microsoft Dynamics NAV 2018 | =2017 | |
Microsoft Dynamics NAV 2018 | =2018 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1724 has a severity rating of medium, indicating a moderate risk to affected systems.
To fix CVE-2021-1724, apply the latest security updates provided by Microsoft for the affected versions of Dynamics 365 Business Central and Dynamics NAV.
CVE-2021-1724 affects Microsoft Dynamics 365 Business Central and Microsoft Dynamics NAV in specific release versions.
CVE-2021-1724 is a cross-site scripting (XSS) vulnerability allowing attackers to execute scripts in the context of a user's session.
The affected versions for CVE-2021-1724 include Microsoft Dynamics 365 Business Central versions 2019 Release Wave 2, 2020 Release Wave 1, 2020 Release Wave 2, and several versions of Dynamics NAV from 2015 to 2018.