PT-2025-46504 · Microsoft · Dynamics 365 Field Service

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-62210

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Dynamics 365 Field Service (online) (affected versions not specified)
Description The issue is a cross-site scripting (XSS) flaw due to improper neutralization of input during web page generation. This allows an authorized attacker to execute arbitrary script code within the web application, potentially leading to spoofing and the theft of user credentials or actions performed on behalf of authenticated users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-14186
CVE-2025-62210

Affected Products

Dynamics 365 Field Service