A flaw discovered in Microsoft's Dynamics CRM could allow remote hackers to trick a logged-in user into inserting malicious code within input fields on vulnerable websites.
Information security company High-Tech Bridge recently unveiled a security report documenting the flaw. According to the firm's security team, while the risk factor of the flaw can be considered low, its existence is still serious. The DOM-based "self-XSS" vulnerability was discovered in Microsoft Dynamics CRM 2013 SP1, which can be exploited to perform cross-site scripting attacks against authentic users of websites.
|