CVE Vulnerabilities

CVE-2021-28399

Published: Apr 26, 2021 | Modified: May 05, 2021
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.

Affected Software

Name Vendor Start Version End Version
Orangehrm Orangehrm 4.7 (including) 4.7 (including)

References