6.5
CVE-2022-28601
- EPSS 5.58%
- Veröffentlicht 10.05.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 06:57:34
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lmsdoctor ≫ 2 Factor Authentication Version- SwPlatformmoodle
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.58% | 0.899 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.