CVE-2024-38166CriticalCVSS 8.2
Microsoft Dynamics 365 Cross-site Scripting Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.
🎯 Affected products1
- Dynamics CRM Service Portal Web Resource