Junglewise Threat Intelligence

CVE-2025-60931: Infor Global HR IDOR in Employee Compensation View

CVE-2025-60931 · Severity: info · CVSS 6.5 · Published 2026-07-29

Executive brief

Infor Global HR, a human resources management platform, contains a security flaw in its employee compensation viewing feature. This vulnerability allows an authenticated employee to view the private salary and pay rate information of other staff members by manipulating web requests. Such an exploit could lead to significant privacy breaches and internal corporate friction if sensitive payroll data is exposed.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Infor Global HR v11.24.10.01.33 and prior within the Employee Compensation View functionality. The root cause is improper authorization checks on the 'EmployeeID' parameter in GET requests to the LRCEmployeeViewCompensation endpoint. While the UI does not display full details immediately, the application includes a search function that accepts a 'Pay Rate' value; an attacker can brute-force this value by monitoring for changes in the HTTP response size or UI position number. Successful exploitation allows an authenticated user to enumerate and confirm the exact pay rates of arbitrary employees across the organization.

Affected products

  • Infor Global HR 11.24.10.01.33 and prior

Timeline

  • 2026-07-29: advisory: NVD publication date

References