Stored Cross-Site Scripting Vulnerabilities in HR Performance Solutions Performance Pro
CVE-2025-60934

Currently unrated

Key Information:

Vendor
CVE Published:
21 October 2025

What is CVE-2025-60934?

Multiple stored cross-site scripting vulnerabilities exist in the index.php component of HR Performance Solutions Performance Pro v3.19.17. These flaws allow attackers to execute arbitrary web scripts or HTML by injecting malicious payloads into the Employee Notes, title, or description parameters. It is crucial for users of this affected version to upgrade to the patched version PP-Release-6.3.2.0 to mitigate the risks associated with these vulnerabilities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-60934 : Stored Cross-Site Scripting Vulnerabilities in HR Performance Solutions Performance Pro