CVE

CVE-2021-28399

CVE-2021-28399

OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.

Source: CVE-2021-28399

Exit mobile version