QID 91801

Date Published: 2021-08-11

QID 91801: Microsoft Dynamics Business Central Cross-Site (XSS) Scripting Vulnerability August 2021

Microsoft Dynamics 365 Business Central is an enterprise resource planning system from Microsoft. The product is part of the Microsoft Dynamics family, and shares the same codebase as NAV.


CVE-2021-36946:Microsoft Dynamics Business Central Cross-site Scripting Vulnerability.

Affected Software:

Dynamics 365 Business Central 2019 Spring Update.
Microsoft Dynamics 365 Business Central 2020 Release Wave 1 - Update 16.15
Microsoft Dynamics 365 Business Central 2020 Release Wave 2 - Update 17.9.
Microsoft Dynamics NAV 2017
Microsoft Dynamics NAV 2018

QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Dynamics.Nav.Server.exe

Successful exploitation allows an attacker to conduct cross-site scripting attacks.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to refer to CVE-2021-36946 for more details pertaining to this vulnerability.

    CVEs related to QID 91801

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-36946 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36946