6.5
CVSSv3

CVE-2022-28601

Published: 10/05/2022 Updated: 23/05/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote malicious users to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lmsdoctor 2 factor authentication -

Github Repositories

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

CVE-2022-28601 A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor Vulnerability Details Risk : Medium Vendor: LMS Doctor - Simple 2 Factor Authentication Plugin For Moodle Disclosed by: Flaviu Popescu Description: Two-Factor Authentication Bypass vulnerability in The Simple 2FA Plugin for Moodle, by "LMS Doctor