PT-2022-19344 · Moodle · Lms Doctor Simple 2 Factor Authentication Plugin

Flaviu Popescu

·

Published

2022-05-10

·

Updated

2022-05-18

·

CVE-2022-28986

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions LMS Doctor Simple 2 Factor Authentication Plugin For Moodle version 2021072900
Description The issue allows remote attackers to update sensitive records, such as email, password, and phone number, of other user accounts due to an Insecure Direct Object References (IDOR) vulnerability.
Recommendations For version 2021072900, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28986

Affected Products

Lms Doctor Simple 2 Factor Authentication Plugin