V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-28601
CVE
MediumConfirmedExploit available

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite…

CVSS
6.5
Medium
EPSS
0.02
p73
Published
2022-01-01
Updated
2022-01-01
Description

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

Tags · CWE
CWE-863
Affected products
2_factor_authentication
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.016 · p73
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2022-28601
github-poc · https://github.com/FlaviuPopescu/CVE-2022-28601
Enterprise
Affected products
ProductVendorStatus
2_factor_authentication*Tracked
Source databases
CVE