CVE-2022-28601
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
- Affected products
- Simple 2Fa Plugin For Moodle
- Lmsdoctor 2 Factor Authentication
- All versions
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-863
- NVD status
- Modified
- Published
- 2022-05-10
CVE-2022-28601 at NVD
1 known exploit for CVE-2022-28601
Proof-of-concept code and exploit modules indexed by Sploitus