Security Advisory

CVE-2022-28601

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-05-10 20:42:50
Last updated 2024-08-03 05:56:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.