CVSS 3.1 Score 7.6 of 10 (high)


Published Feb 13, 2024
Updated: Feb 23, 2024


CVE-2024-21393 is a cross-site scripting vulnerability found in Microsoft Dynamics 365 (on-premises). It affects various products, including s-pbLs, sI_3qm, umfRXF, s-pbLr, tCwJbe, j6yBnG, and tex_C1. The vulnerability has a risk score of 25 and a base severity of HIGH. It requires LOW privileges to be exploited and user interaction is required. The attack vector is through the NETWORK and the impact includes LOW integrity and HIGH confidentiality. The vulnerability can be remediated by implementing proper input validation during web page generation. This vulnerability poses a potential danger to organizations using Microsoft Dynamics 365 (on-premises) as it can lead to unauthorized access and data exposure.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-21393 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options