CVE-2021-40457HighCVSS 7.4
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? A user would have to open a maliciously crafted email sent to Dynamics 365 Customer Engagement.
🎯 Affected products2
- Microsoft Dynamics 365 Customer Engagement V9.0
- Microsoft Dynamics 365 Customer Engagement V9.1
✅ Remediation
KB4618810 (Security Update) — fixed build 9.1.4 KB4618795 (Security Update) — fixed build 9.0.31.7