🟡 Medium  |  Source: Microsoft Security Response Center


CVE-2021-40440 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. XSS flaws allow attackers to inject malicious scripts into web pages viewed by other users, potentially stealing session tokens or credentials. This update revises the affected build numbers but introduces no new patches or changed risk ratings.

Security Architect’s Take: Verify that your Dynamics 365 Business Central instances are running patched build numbers as now listed in the updated advisory, and confirm that your Content Security Policy (CSP) headers are correctly configured to reduce XSS exposure as a defence-in-depth measure.

Original advisory: CVE-2021-40440 Microsoft Dynamics Business Central Cross-site Scripting Vulnerability