Medium severity5.3NVD Advisory· Published Apr 26, 2021· Updated Jun 17, 2026
CVE-2021-28399
CVE-2021-28399
Description
OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- OrangeHRM/OrangeHRMdescription
Patches
Vulnerability mechanics
References
2- github.com/C1inton/CVE-Record/blob/master/CVE%20Record/%5BCVE-2021-28399%5DOrangeHRM%204.7.mdnvdBroken LinkThird Party Advisory
- www.orangehrm.comnvdVendor Advisory
News mentions
0No linked articles in our index yet.