❗Reflected XSS
Infor Global HR v11.23.03.00.21 and prior is affected by Reflected XSS (AKA Non-Persistent or Type I) vulnerability.
Reflected XSS (authenticated)
CVE-2024-51423
Infor Global HR v11.23.03.00.21 and prior is affected by a Reflected XSS (AKA Non-Persistent or Type I) vulnerability via the {class} parameter in Error Message Rendering. Authentication is required.
{class} parameter in Error Message Rendering. Authentication is required. Description
Exploitation
Example 1 - Simple JavaScript Alert Injection

Example 2 - Remote JavaScript Injection for Data Theft


Last updated