CVE-2021-28399
26.04.2021, 14:15
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.Enginsight
Vendor | Product | Version |
---|---|---|
orangehrm | orangehrm | 4.7 |
𝑥
= Vulnerable software versions