CERT-In Vulnerability Note
CIVN-2018-0209
Cross Scripting Vulnerability in Microsoft Dynamics NAV
Original Issue Date:December 12, 2018
Severity Rating: LOW
Software Affected
- Microsoft Dynamics NAV 2016
- Microsoft Dynamics NAV 2017
Overview
A Vulnerability has been reported in Microsoft Dynamics NAV which could allow remote attacker to execute arbitrary code on the targeted system.
Description
A cross site scripting vulnerability exists in Microsoft Dynamics NAV due to improperly handling web requests by the affected Dynamics NAV server. A remote attacker could exploit this vulnerability by sending a specially crafted request to an affected Dynamics NAV server.
Successful exploitation of this vulnerability could allow an attacker to perform cross-site scripting attacks on affected systems and run script in the security context of the current user, to launch the further attacks.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
https://portal.msrc.microsoft.com/en-us/security-guidance
Vendor Information
Microsoft
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8651
References
Microsoft
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8651
CVE Name
CVE-2018-8651
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|