PT-2025-46505 · Microsoft · Dynamics 365 Field Service

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-62211

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Dynamics 365 Field Service (online) (affected versions not specified)
Description The issue involves improper neutralization of input during web page generation, leading to a cross-site scripting condition. An authorized attacker can perform spoofing over a network by exploiting this. The core of the issue is that user inputs are not sufficiently sanitized or encoded when rendered, allowing an attacker to inject malicious scripts into webpages viewed by legitimate users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-14079
CVE-2025-62211

Affected Products

Dynamics 365 Field Service