PT-2022-19344 · Moodle · Lms Doctor Simple 2 Factor Authentication Plugin
Flaviu Popescu
·
Published
2022-05-10
·
Updated
2022-05-18
·
CVE-2022-28986
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle version 2021072900
Description
The issue allows remote attackers to update sensitive records, such as email, password, and phone number, of other user accounts due to an Insecure Direct Object References (IDOR) vulnerability.
Recommendations
For version 2021072900, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lms Doctor Simple 2 Factor Authentication Plugin