CVE-2025-60931 Details
Description
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Employee Compensation View function of Infor Global HR version 11.24.10.01.33. This vulnerability allows unauthorized attackers to view the compensation information of other employees by sending a crafted GET request.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 29, 2026CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.offsecguy.com/cve/infor/vulnerability/insecure-direct-object-references-idor | CISA-ADP | Technical Description |
| https://docs.offsecguy.com/cve/infor/vulnerability/insecure-direct-object-references-idor | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Infor Global HR | 11.24.10.01.33 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |
Volerion