Impact
The vulnerability is an improper neutralization of user input during web page generation, classified as a Cross‑Site Scripting flaw (CWE‑79). It allows an unauthorized attacker to inject malicious content into pages served by Dynamics 365 Customer Voice, making other users believe the attacker is a legitimate participant or source. This deception can erode trust and potentially enable further phishing or social engineering attacks.
Affected Systems
Microsoft Dynamics 365 Customer Voice is affected. No specific version list is provided by the CNA; therefore all deployed instances of the product may be vulnerable until patched.
Risk and Exploitability
The CVSS score is 9.3, indicating a high‑severity risk. The EPSS score is < 1 %, showing a very low but nonzero likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by supplying crafted input that is reflected or stored without proper sanitization, enabling the delivery of deceptive content that appears authentic to other users. Because the flaw does not require authentication, any user interacting with the web interface could be impacted.
OpenCVE Enrichment