---
id: CVE-2025-60931
title: >-
  An Insecure Direct Object Reference (IDOR) in the Employee Compensation View
  function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to
  arbitrarily view the compensation information of other employees via a crafted
  GET …
summary: >-
  An Insecure Direct Object Reference (IDOR) in the Employee Compensation View
  function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to
  arbitrarily view the compensation information of other employees via a crafted
  GET …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
published: '2026-07-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T18:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-60931'
references:
  - url: >-
      https://docs.offsecguy.com/cve/infor/vulnerability/insecure-direct-object-references-idor
    label: cve@mitre.org
  - url: >-
      https://docs.offsecguy.com/cve/infor/vulnerability/insecure-direct-object-references-idor
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00394
epssPercentile: 0.31229
ingestedAt: '2026-10-05T18:29:11.177Z'
---

## Overview

An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
