CVE-2021-28399

EUVD-2021-15079
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N