CVE-2024-51423

Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execute arbitrary code via the class parameter.
References
Link Resource
https://docs.offsecguy.com/cve/infor/vulnerability/reflected-xss Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:infor:global_human_resources:*:*:*:*:*:*:*:*

History

10 Sep 2025, 18:55

Type Values Removed Values Added
CPE cpe:2.3:a:infor:global_human_resources:*:*:*:*:*:*:*:*
References () https://docs.offsecguy.com/cve/infor/vulnerability/reflected-xss - () https://docs.offsecguy.com/cve/infor/vulnerability/reflected-xss - Exploit, Third Party Advisory
First Time Infor
Infor global Human Resources

02 Sep 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

02 Sep 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-02 16:15

Updated : 2025-09-10 18:55


NVD link : CVE-2024-51423

Mitre link : CVE-2024-51423

CVE.ORG link : CVE-2024-51423


JSON object : View

Products Affected

infor

  • global_human_resources
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')