QID 91817

Date Published: 2021-09-15

QID 91817: Microsoft Dynamics Business Central Cross-Site Scripting (XSS) Vulnerability September 2021

Microsoft Dynamics 365 Business Central is an enterprise resource planning system from Microsoft. The product is part of the Microsoft Dynamics family, and shares the same codebase as NAV.


CVE-2021-40440:Microsoft Dynamics Business Central Cross-site Scripting Vulnerability.

Affected Software:

Microsoft Dynamics 365 Business Central 2021 Release Wave 1 - Update 18.5
Microsoft Dynamics 365 Business Central 2020 Release Wave 2 - Update 17.10.

QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Dynamics.Nav.Server.exe

Successful exploitation allows an attacker to conduct cross-site scripting attacks.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to refer to CVE-2021-40440 for more details pertaining to this vulnerability.

    CVEs related to QID 91817

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-40440 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40440