CVE-2012-1857

Microsoft Dynamics AX 2012 - Cross-Site Scripting via Crafted URL

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."

References (2)

Core 2
Core References
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA12-164A.html

Scores

EPSS 0.1101
EPSS Percentile 95.5%

Details

CWE
CWE-79
Status published
Products (1)
microsoft/dynamics_ax 2012
Published Jun 12, 2012
Tracked Since Feb 18, 2026