CVE-2021-28399
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password f
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.
MEDIUM · CVSS 5.3
EPSS 0.00711
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0