SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-60931

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Employee Compensation View function in Infor Global HR v11.24.10.01.33 is vulnerable to an Insecure Direct Object Reference (IDOR), enabling unauthorized users to access sensitive compensation data of other employees through specially crafted GET requests. This vulnerability poses a significant risk to employee privacy and data security. Organizations using this version of Infor Global HR should prioritize patching to mitigate potential data breaches.

CVE
CVE-2025-60931
Severity
HIGH
CVSS
7.5
EPSS
0.23%

Original NVD Description

An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.