Sploitus

CVE-2022-28601

1 known exploit for CVE-2022-28601

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

Lmsdoctor 2 Factor Authentication
All versions
CVSS 3.1
6.5 MEDIUM
EPSS
1.7% (75th percentile)
Weakness
CWE-863
NVD status
Modified
Published
2022-05-10
CVE-2022-28601 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-28601

Proof-of-concept code and exploit modules indexed by Sploitus