Vulnerabilities > CVE-2022-28601 - Incorrect Authorization vulnerability in Lmsdoctor 2 Factor Authentication
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |