A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-05-10T20:42:50

Updated: 2024-08-03T05:56:16.203Z

Reserved: 2022-04-04T00:00:00

Link: CVE-2022-28601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-05-10T21:15:11.077

Modified: 2022-05-23T16:29:07.000

Link: CVE-2022-28601

cve-icon Redhat

No data.