Impact
The issue is an improper neutralization of user input during web page generation, classified as a Cross‑Site Scripting flaw (CWE‑79). An attacker with no authentication can inject malicious content into pages served by Dynamics 365 Customer Voice, causing other users to perceive the injected content as originating from a legitimate source and potentially leading to confusion or other deception attempts.
Affected Systems
Microsoft Dynamics 365 Customer Voice is affected. No specific affected version list is provided by the CNA; therefore all deployed instances of the product may be vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity risk, while the EPSS score of < 1 % shows a very low but nonzero likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by supplying crafted input that is reflected or stored without proper sanitization, enabling the delivery of deceptive content that appears authentic to other users. Because the flaw does not require authentication, any user interacting with the web interface could be impacted.
OpenCVE Enrichment