Security Advisory

CVE-2024-49038

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-11-26 19:43:35
Last updated 2025-06-16 02:44:10
Assigner microsoft
State PUBLISHED

Description

Improper neutralization of input during web page generation (Cross-site Scripting) in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.