Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43909 | Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. |
Thu, 09 Jan 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft copilot Studio |
|
| CPEs | cpe:2.3:a:microsoft:copilot_studio:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft copilot Studio |
Tue, 10 Dec 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Microsoft
Microsoft copilot Studio |
Tue, 26 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 Nov 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. | |
| Title | Microsoft Copilot Studio Elevation Of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft copilot Studio |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:microsoft:copilot_studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft copilot Studio |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-07-08T15:41:27.083Z
Reserved: 2024-10-11T20:57:49.186Z
Link: CVE-2024-49038
Updated: 2024-11-26T19:57:27.255Z
Status : Analyzed
Published: 2024-11-26T20:15:31.943
Modified: 2025-01-09T19:30:34.403
Link: CVE-2024-49038
No data.
OpenCVE Enrichment
No data.
EUVD