A critical (CVSS 9.3) cross-site scripting vulnerability in Microsoft Dynamics 365 allows a remote, anonymous attacker to execute arbitrary scripts. The specific attack vector is not detailed, but the vulnerability affects the Microsoft Dynamics 365 Customer Voice product. A mitigation is available, but the article does not specify the exact affected version ranges, a fixed version, or the nature of the workaround.
[WID-SEC-2026-2019] Microsoft Dynamics 365: Schwachstelle ermöglicht Cross-Site Scripting CVSS Base Score 9.3 (kritisch) CVSS Temporal Score 8.1 (hoch) Remoteangriff ja Datum 21.06.2026 Stand 22.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Windows Produktbeschreibung Microsoft Dynamics 365 ist eine All-in-One-Unternehmensmanagementlösung. Produkte 21.06.2026 Microsoft Dynamics 365 Customer Voice Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Microsoft Dynamics 365 ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben