SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-28601

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file.

MEDIUM 6.5EPSS 1.71%

Does this matter?

Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.

Description

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
1.71% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
lmsdoctor/2 factor authentication
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.