CVE-2020-1049 describes a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that arises from insufficient sanitization of specially crafted web requests. This flaw could allow an attacker to inject malicious scripts into affected Dynamics servers. Rated with a CVSS score of 5.4 (Medium), the vulnerability requires user interaction (UI:R) and low privileges (PR:L) for exploitation over a network (AV:N). Successful exploitation could lead to limited confidentiality and integrity impacts (C:L/I:L), but not availability (A:N). There is no evidence of active exploitation, and no public exploit code is available via Metasploit, Nuclei, or ExploitDB. While it received limited community discussion and media coverage at the time of its disclosure, its EPSS score indicates a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_server:9.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.