QID 91817
Date Published: 2021-09-15
QID 91817: Microsoft Dynamics Business Central Cross-Site Scripting (XSS) Vulnerability September 2021
Microsoft Dynamics 365 Business Central is an enterprise resource planning system from Microsoft. The product is part of the Microsoft Dynamics family, and shares the same codebase as NAV.
CVE-2021-40440:Microsoft Dynamics Business Central Cross-site Scripting Vulnerability.
Affected Software:
Microsoft Dynamics 365 Business Central 2021 Release Wave 1 - Update 18.5
Microsoft Dynamics 365 Business Central 2020 Release Wave 2 - Update 17.10.
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Dynamics.Nav.Server.exe
Successful exploitation allows an attacker to conduct cross-site scripting attacks.
Solution
Customers are advised to refer to CVE-2021-40440 for more details pertaining to this vulnerability.
Vendor References
- CVE-2021-40440 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40440
CVEs related to QID 91817
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-40440 |
|