PT-2025-42890 · Hr Performance Solutions · Performance Pro

Published

2025-10-21

·

Updated

2025-10-21

·

CVE-2025-60933

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HR Performance Solutions Performance Pro versions prior to 6.3.2.0
Description The software contains multiple stored cross-site scripting (XSS) issues within the Future Goals function. These issues allow attackers to inject crafted payloads into several parameters, potentially leading to the execution of arbitrary web scripts or HTML. The affected parameters include Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name, and Goal Description.
Recommendations Update to version 6.3.2.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60933

Affected Products

Performance Pro