An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.
CVE ID: CVE-2024-38166
CVSS Base Severity: HIGH
CVSS Base Score: 8.2
Vendor: Microsoft
Product: Dynamics CRM Service Portal Web Resource
EPSS Score: 0.08% (probability of being exploited)
EPSS Percentile: 37.37% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)