5
CVSSv2

CVE-2022-28986

Published: 10/05/2022 Updated: 18/05/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote malicious users to update sensitive records such as email, password and phone number of other user accounts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lmsdoctor 2 factor authentication 2021072900

Github Repositories

A Insecure direct object references (IDOR) vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

CVE-2022-28986 A Insecure direct object references (IDOR) vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor Vulnerability Details Risk : Critical Vendor: LMS Doctor - Simple 2 Factor Authentication Plugin For Moodle Disclosed by: Flaviu Popescu Description: Insecure direct object references (IDOR) vulnerability in The Simple 2FA Plugin for Moodle by "