🟡 Medium  |  Source: Microsoft Security Response Center


CVE-2021-36946 is a cross-site scripting (XSS) vulnerability affecting Microsoft Dynamics Business Central, a cloud-based ERP platform. XSS flaws allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking or credential theft. This update revises the affected build numbers and is informational in nature — no new patches are being issued.

Security Architect’s Take: Verify that your Dynamics Business Central deployments are running patched build versions as newly listed in the updated advisory. If you have not already applied the original fix, prioritise doing so and review Content Security Policy (CSP) headers on any Business Central web client deployments to reduce XSS exposure.

Original advisory: CVE-2021-36946 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability