> For the complete documentation index, see [llms.txt](https://docs.offsecguy.com/cve/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.offsecguy.com/cve/infor/infor-global-hr-or-reflected-cross-site-scripting-xss-disclosure.md).

# Infor Global HR | Reflected Cross-Site Scripting (XSS) Disclosure

Discoverer: Paul Goodrich, Giovanni Heward, Adam Hainline, Tyler Gleave, Dan Gilbert

<figure><img src="https://2726485956-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPjlUotWgSJsfjiu9Q8HP%2Fuploads%2FCS9Y56IDDt0S1ZVIpPgs%2Fimage.png?alt=media&amp;token=06067b6f-6929-4008-a1af-0054272255d6" alt=""><figcaption><p>Tested v11.23.03.00.21 - Prior versions are affected.</p></figcaption></figure>

## Summary of Findings

* [Cross-Site Scripting (XSS) - Reflected](/cve/infor/vulnerability/reflected-xss.md)
  * [CVE-2024-51423](/cve/infor/vulnerability/reflected-xss.md)
* ​[Insecure Direct Object Reference (IDOR)](/cve/infor/vulnerability/insecure-direct-object-references-idor.md)
  * [CVE-2025-60931](/cve/infor/vulnerability/insecure-direct-object-references-idor.md)

### Timeline

* Reported to Vendor: Oct 24th, 2024
* Patched: Jan, 2025
* Published: Sept 2, 2025
