VulnerabilityModified
CVE-2022-28601
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file.
MEDIUM 6.5EPSS 1.71%
Does this matter?
Lower severity and a low EPSS score (1.71%). Track it; it rarely justifies an emergency change on its own.
Description
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- lmsdoctor/2 factor authentication
- Source
- cve@mitre.org
References
- https://github.com/FlaviuPopescu/CVE-2022-28601Exploit, Third Party Advisory
- https://www.lmsdoctor.com/simple-2-factor-authentication-plugin-for-moodleProduct
- https://github.com/FlaviuPopescu/CVE-2022-28601Exploit, Third Party Advisory
- https://www.lmsdoctor.com/simple-2-factor-authentication-plugin-for-moodleProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.