CVE-2021-28461: Dynamics Finance and Operations Cross-site Scripting Vulnerability

Overview

Severity
Medium (CVSS 6.1)
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-May
Released
2021-05-11
Last Updated
2021-05-26
EPSS Score
2.42% (percentile: 85.1%)

Affected Products (1)

Microsoft Dynamics

  • Dynamics 365 for Finance and Operations

Security Updates (1)

Acknowledgments

<a href="https://www.linkedin.com/in/erfan-fazeli-092289b4/">Mico Fraxix</a>, Joseph Rapley, Mohammad Deilamy(MDM), Mohammad Deilamy(MDM), Mohammad Deilamy(MDM), Mohammad Deilamy(MDM)

Revision History

  • 2021-05-11: Information published.
  • 2021-05-13: In the Security Updates table, added links to the Release Notes. This is an informational change only.
  • 2021-05-26: Added an acknowledgement. This is an informational change only.