PT-2025-42889 · Hr Performance Solutions · Performance Pro

Published

2025-10-21

·

Updated

2025-10-21

·

CVE-2025-60932

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HR Performance Solutions Performance Pro versions prior to 6.3.2.0
Description The Current Goals function contains multiple stored cross-site scripting (XSS) issues. Attackers can inject crafted payloads into several parameters to execute arbitrary web scripts or HTML. The affected parameters include Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name, and Goal Description.
Recommendations Update to version 6.3.2.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60932

Affected Products

Performance Pro