PT-2022-19098 · Moodle · Simple 2Fa Plugin For Moodle

Flaviu Popescu

·

Published

2022-05-10

·

Updated

2022-05-23

·

CVE-2022-28601

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Simple 2FA Plugin for Moodle (affected versions not specified)
Description A Two-Factor Authentication (2FA) bypass issue allows remote attackers to overwrite the phone number used for confirmation via the "profile.php" file, thereby bypassing the phone verification mechanism.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28601

Affected Products

Simple 2Fa Plugin For Moodle